CVE-2020-1918

In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the in-memory buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.94.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.95.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.96.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.97.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.98.0:*:*:*:*:*:*:*

History

15 Mar 2021, 15:53

Type Values Removed Values Added
References (MISC) https://github.com/facebook/hhvm/commit/08193b7f0cd3910256e00d599f0f3eb2519c44ca - (MISC) https://github.com/facebook/hhvm/commit/08193b7f0cd3910256e00d599f0f3eb2519c44ca - Patch, Third Party Advisory
References (MISC) https://hhvm.com/blog/2021/02/25/security-update.html - (MISC) https://hhvm.com/blog/2021/02/25/security-update.html - Release Notes, Vendor Advisory
CPE cpe:2.3:a:facebook:hhvm:4.96.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.98.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.94.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.97.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.95.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*
CWE CWE-125
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5

10 Mar 2021, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2021-03-10 16:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-1918

Mitre link : CVE-2020-1918

CVE.ORG link : CVE-2020-1918


JSON object : View

Products Affected

facebook

  • hhvm
CWE
CWE-125

Out-of-bounds Read

CWE-127

Buffer Under-read