CVE-2020-1918

HIGH

Facebook HHVM - Out-of-Bounds Read via Negative Seeking in In-Memory File Operations

Title source: llm
STIX 2.1

Description

In-memory file operations (ie: using fopen on a data URI) did not properly restrict negative seeking, allowing for the reading of memory prior to the in-memory buffer. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory x_refsource_misc
https://hhvm.com/blog/2021/02/25/security-update.html

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-125 CWE-127
Status published
Products (6)
facebook/hhvm 4.94.0
facebook/hhvm 4.95.0
facebook/hhvm 4.96.0
facebook/hhvm 4.97.0
facebook/hhvm 4.98.0
facebook/hhvm < 4.56.3
Published Mar 10, 2021
Tracked Since Feb 18, 2026