Buffer Re-use Vulnerability in HHVM and Folly Library
CVE-2018-6337
7.5HIGH
What is CVE-2018-6337?
A vulnerability in the HHVM and Folly library arises when the secureRandom function re-uses a buffer between parent and child processes after a fork() call. This behavior may lead to multiple forked children generating similar or identical outputs, compromising the randomness required for secure operations. Users of HHVM versions earlier than 3.26.3 and the folie library versions between 2017.12.11.00 and 2018.08.09.00 are particularly affected. It is crucial for users to update to patched versions to mitigate this issue.
Affected Version(s)
folly v2018.08.09.00
folly v2017.12.11.00
HHVM 3.26.3
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved