CVE-2016-6873: Critical severity Facebook HHVM vulnerability
Published Feb 17, 2017
·Updated
Self recursion in compact in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
Affected Software
1 affected component
Facebook HHVM<=3.14.5
Remediation
Event History
Feb 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6873?
The severity of CVE-2016-6873 is not explicitly rated, but it allows for unspecified impact via unknown vectors.
2
How do I fix CVE-2016-6873?
To fix CVE-2016-6873, upgrade Facebook HHVM to version 3.15.0 or later.
3
Which versions of HHVM are affected by CVE-2016-6873?
CVE-2016-6873 affects all versions of Facebook HHVM prior to 3.15.0, up to and including 3.14.5.
4
What type of vulnerability is CVE-2016-6873?
CVE-2016-6873 is a self recursion vulnerability in the compact function of Facebook HHVM.
5
Can CVE-2016-6873 be exploited remotely?
The details of the vectors are unspecified, but vulnerabilities like CVE-2016-6873 could potentially be exploited remotely depending on the implementation.