First published: Mon Dec 03 2018(Updated: )
A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources. This affects all supported versions of HHVM (3.24.3 and 3.21.7 and below) when using the proxygen server to handle HTTP2 requests.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook HHVM | <=3.21.7 | |
Facebook HHVM | =3.24.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6332 is a potential denial-of-service issue in the Proxygen handling of invalid HTTP2 settings which can cause the server to spend disproportionate resources.
The affected versions of HHVM are 3.24.3 and 3.21.7 and below.
The severity of CVE-2018-6332 is medium with a severity value of 5.9.
CVE-2018-6332 can be exploited by sending invalid HTTP2 settings to the Proxygen server, causing it to allocate excessive resources.
To mitigate CVE-2018-6332, update HHVM to version 3.25 or later, as the issue is fixed in that release.