First published: Mon Dec 31 2018(Updated: )
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook HHVM | <=3.27.4 | |
Facebook HHVM | =3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-6340.
The severity of CVE-2018-6340 is high with a CVSS score of 8.1.
The affected software is Facebook HHVM versions up to 3.27.4 and version 3.30.
Exploiting CVE-2018-6340 requires control over memcached server hostnames and/or ports.
Yes, patches and fixes for CVE-2018-6340 are available. Please refer to the references for more information.