CVE-2016-1000005

CRITICAL

HHVM <3.9.5, 3.10.0-3.12.3, 3.13.0-3.14.1 - Type Confusion

Title source: llm
STIX 2.1

Description

mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://www.facebook.com/security/advisories/cve-2016-1000005

Scores

CVSS v3 9.8
EPSS 0.0053
EPSS Percentile 67.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-843
Status published
Products (1)
facebook/hhvm < 3.9.5
Published Feb 19, 2020
Tracked Since Feb 18, 2026