CVE-2020-1916

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
10/03/2021
Last modified:
17/03/2021

Description

An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all versions between 4.57.0 and 4.78.0, 4.79.0, 4.80.0, 4.81.0, 4.82.0, 4.83.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* 4.56.2 (excluding)
cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* 4.57.0 (including) 4.78.1 (excluding)
cpe:2.3:a:facebook:hhvm:4.79.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.80.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.81.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.82.0:*:*:*:*:*:*:*
cpe:2.3:a:facebook:hhvm:4.83.0:*:*:*:*:*:*:*