CVE-2016-6870: Critical severity Facebook HHVM vulnerability
Published Feb 17, 2017
·Updated
Out-of-bounds write in the (1) mbdetectencoding, (2) mbsendmail, and (3) mbdetectorder functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
Affected Software
1 affected component
Facebook HHVM<=3.14.5
Remediation
Patch Available
Patch Available
Event History
Feb 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6870?
CVE-2016-6870 is considered a high severity vulnerability due to the risk of an out-of-bounds write affecting multiple functions.
2
How do I fix CVE-2016-6870?
To fix CVE-2016-6870, upgrade Facebook HHVM to version 3.15.0 or later.
3
What versions of HHVM are affected by CVE-2016-6870?
CVE-2016-6870 affects all versions of Facebook HHVM prior to 3.15.0, specifically up to version 3.14.5.
4
What functions are vulnerable in CVE-2016-6870?
CVE-2016-6870 impacts the mb_detect_encoding, mb_send_mail, and mb_detect_order functions.
5
Can CVE-2016-6870 be exploited remotely?
Yes, CVE-2016-6870 can be exploited remotely through unknown vectors, posing a security threat to applications using HHVM.