CVE-2020-1898

The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to recurse, leading to stack exhaustion. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.57.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.58.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.58.1:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.59.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.60.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.61.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.62.0:*:*:*:*:*:*:*

History

17 Mar 2021, 19:50

Type Values Removed Values Added
References (CONFIRM) https://hhvm.com/blog/2020/06/30/security-update.html - (CONFIRM) https://hhvm.com/blog/2020/06/30/security-update.html - Vendor Advisory
References (MISC) https://github.com/facebook/hhvm/commit/1746dfb11fc0048366f34669e74318b8278a684c - (MISC) https://github.com/facebook/hhvm/commit/1746dfb11fc0048366f34669e74318b8278a684c - Patch, Third Party Advisory
CPE cpe:2.3:a:facebook:hhvm:4.60.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.58.1:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.62.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.58.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.59.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.61.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.57.0:*:*:*:*:*:*:*
CWE CWE-674
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

11 Mar 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-11 01:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-1898

Mitre link : CVE-2020-1898

CVE.ORG link : CVE-2020-1898


JSON object : View

Products Affected

facebook

  • hhvm
CWE
CWE-674

Uncontrolled Recursion