CVE-2018-6337

HIGH

HHVM <3.26.3 - Buffer Overflow

Title source: llm
STIX 2.1

Description

folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119 CWE-212
Status published
Products (2)
facebook/folly 2017.12.11.00 - 2018.08.09.00
facebook/hhvm 3.26 - 3.26.3
Published Dec 31, 2018
Tracked Since Feb 18, 2026