CVE-2016-6874: Critical severity Facebook HHVM vulnerability
Published Feb 17, 2017
·Updated
The arrayrecursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion.
Affected Software
1 affected component
Facebook HHVM<=3.14.5
Event History
Feb 17, 2017
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Data Sourced
via NVD·05:59 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6874?
The severity of CVE-2016-6874 is not explicitly rated but it allows attackers to potentially exploit recursion vulnerabilities.
2
How do I fix CVE-2016-6874?
To fix CVE-2016-6874, upgrade Facebook HHVM to version 3.15.0 or later.
3
Which versions of Facebook HHVM are affected by CVE-2016-6874?
Facebook HHVM versions before 3.15.0, specifically up to version 3.14.5, are affected by CVE-2016-6874.
4
What functionality is impacted by CVE-2016-6874?
CVE-2016-6874 impacts the array_*_recursive functions in Facebook HHVM, allowing for potential recursion issues.
5
Are there any known exploits for CVE-2016-6874?
There are currently unspecified impact vectors related to CVE-2016-6874, but no specific public exploits have been reported.