CVE-2014-1439: Medium severity Hiphop Virtual Machine For Php Project Hiphop Virtual Machine For Php vulnerability
The libxmldisableentityloader function in runtime/ext/extsimplexml.cpp in HipHop Virtual Machine for PHP (HHVM) before 2.4.0 and 2.3.x before 2.3.3 does not properly disable a certain libxml handler, which allows remote attackers to conduct XML External Entity (XXE) attacks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HipHop Virtual Machine for PHP (HHVM)to a version that resolves this vulnerability.Fixed in 2.4.0 - Upgrade
Upgrade
HipHop Virtual Machine for PHP (HHVM)to a version that resolves this vulnerability.Fixed in 2.3.3
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1439?
CVE-2014-1439 has a medium severity rating due to its potential for XML External Entity (XXE) attacks.
How do I fix CVE-2014-1439?
To mitigate CVE-2014-1439, upgrade HipHop Virtual Machine for PHP to version 2.4.0 or later.
Which versions of HipHop Virtual Machine for PHP are affected by CVE-2014-1439?
CVE-2014-1439 affects HipHop Virtual Machine versions before 2.4.0, including all 2.3.x versions before 2.3.3.
What type of attacks can CVE-2014-1439 allow?
CVE-2014-1439 can allow remote attackers to conduct XML External Entity (XXE) attacks.
Is CVE-2014-1439 specific to any programming language?
Yes, CVE-2014-1439 specifically affects applications using HipHop Virtual Machine for PHP.