CVE-2018-6334
Summary
| CVE | CVE-2018-6334 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-31 19:29:00 UTC |
| Updated | 2019-10-09 23:41:00 UTC |
| Description | Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This affects all supported versions of HHVM prior to the patch (3.25.1, 3.24.5, and 3.21.9 and below). |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| HHVM 3.25.2, HHVM 3.24.6, and 3.21.10 (CVE-2018-6334) | HHVM | MISC | hhvm.com | Patch, Third Party Advisory |
| [security][CVE-2018-6334] kill globals for file uploads in hhvm · facebook/hhvm@6937de5 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.