First published: Tue Nov 19 2019(Updated: )
hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/hhvm | <3.12.11+dfsg-1 | 3.12.11+dfsg-1 |
<3.12.11 | ||
Facebook HHVM | <3.12.11 | |
debian/hhvm |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1000006 is a vulnerability in hhvm before version 3.12.11 that allows for a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.
CVE-2016-1000006 can lead to a use-after-free vulnerability in hhvm before version 3.12.11, which could potentially allow an attacker to execute arbitrary code or cause a denial of service.
CVE-2016-1000006 has a severity rating of 9.8, which is considered critical.
To fix CVE-2016-1000006, you should update hhvm to version 3.12.11 or later.
You can find more information about CVE-2016-1000006 at the following references: [1] [2] [3].