First published: Wed Oct 02 2019(Updated: )
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook HHVM | <3.30.10 | |
Facebook HHVM | >=4.0.0<=4.8.5 | |
Facebook HHVM | >=4.9.0<=4.18.2 | |
Facebook HHVM | =4.19.0 | |
Facebook HHVM | =4.19.1 | |
Facebook HHVM | =4.20.0 | |
Facebook HHVM | =4.20.1 | |
Facebook HHVM | =4.20.2 | |
Facebook HHVM | =4.21.0 | |
Facebook HHVM | =4.22.0 | |
Facebook HHVM | =4.23.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11929 is a vulnerability in HHVM that allows for read/write access to out-of-bounds memory, potentially leading to remote code execution.
HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0 to 4.23.0 are affected.
The severity of CVE-2019-11929 is critical with a CVSS score of 9.8.
To fix CVE-2019-11929, update HHVM to version 3.30.10 or newer, version 4.8.6 or newer, version 4.18.3 or newer, or version 4.23.1 or newer.
You can find more information about CVE-2019-11929 on the GitHub page for the HHVM commit addressing the vulnerability, the HHVM blog, and the Facebook security advisories page.