CVE-2018-6345

CRITICAL

Facebook Hhvm < 3.27.5 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

The function number_format is vulnerable to a heap overflow issue when its second argument ($dec_points) is excessively large. The internal implementation of the function will cause a string to be created with an invalid length, which can then interact poorly with other functions. This affects all supported versions of HHVM (3.30.1 and 3.27.5 and below).

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://hhvm.com/blog/2019/01/14/hhvm-3.30.2.html

Scores

CVSS v3 9.8
EPSS 0.0092
EPSS Percentile 76.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-122 CWE-787
Status published
Products (1)
facebook/hhvm < 3.27.5
Published Jan 15, 2019
Tracked Since Feb 18, 2026