CVE-2019-11935
Summary
| CVE | CVE-2019-11935 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-04 17:16:00 UTC |
| Updated | 2019-12-11 18:32:00 UTC |
| Description | Insufficient boundary checks when processing a string in mb_ereg_replace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1. |
Risk And Classification
Problem Types: CWE-120
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hhvm | All | All | All | All | |
| Application | Hhvm | 4.24.0 | All | All | All | |
| Application | Hhvm | 4.25.0 | All | All | All | |
| Application | Hhvm | 4.26.0 | All | All | All | |
| Application | Hhvm | 4.27.0 | All | All | All | |
| Application | Hhvm | 4.28.0 | All | All | All | |
| Application | Hhvm | 4.28.1 | All | All | All | |
| Application | Hhvm | All | All | All | All | |
| Application | Hhvm | 4.24.0 | All | All | All | |
| Application | Hhvm | 4.25.0 | All | All | All | |
| Application | Hhvm | 4.26.0 | All | All | All | |
| Application | Hhvm | 4.27.0 | All | All | All | |
| Application | Hhvm | 4.28.0 | All | All | All | |
| Application | Hhvm | 4.28.1 | All | All | All | |
| Application | Hhvm | All | All | All | All | |
| Application | Hhvm | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Update | HHVM | CONFIRM | hhvm.com | Vendor Advisory |
| Fix buffer overflow in mb_ereg_replace · facebook/hhvm@1c51855 · GitHub | CONFIRM | github.com | Patch, Third Party Advisory |
| CONFIRM | www.facebook.com | Vendor Advisory | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.