Input Truncation Vulnerability in HHVM by Facebook
CVE-2019-11936

9.8CRITICAL

Key Information:

Vendor

Facebook

Status
Vendor
CVE Published:
4 December 2019

What is CVE-2019-11936?

An identified vulnerability in HHVM allows various APC functions to accept keys with null byte characters, leading to premature input truncation. This flaw affects multiple versions of HHVM, from earlier builds to more recent ones, enabling unexpected behavior in applications relying on this PHP execution environment. Corrective measures are essential for developers using HHVM to secure their applications and mitigate potential exploitation risks.

Affected Version(s)

HHVM 4.28.2

HHVM 4.28.0

HHVM 4.27.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-11936 : Input Truncation Vulnerability in HHVM by Facebook