CVE-2018-6340: High severity facebook hiphop virtual machine vulnerability
Published Dec 31, 2018
·Updated
The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
Affected Software
2 affected components
Facebook HHVM<=3.27.4
Facebook HHVM=3.30
Remediation
Event History
Dec 31, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-6340.
2
What is the severity of CVE-2018-6340?
The severity of CVE-2018-6340 is high with a CVSS score of 8.1.
3
Which software is affected by CVE-2018-6340?
The affected software is Facebook HHVM versions up to 3.27.4 and version 3.30.
4
How can CVE-2018-6340 be exploited?
Exploiting CVE-2018-6340 requires control over memcached server hostnames and/or ports.
5
Are there any patches or fixes available for CVE-2018-6340?
Yes, patches and fixes for CVE-2018-6340 are available. Please refer to the references for more information.