First published: Wed Dec 04 2019(Updated: )
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Credit: cve-assign@fb.com cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Facebook HHVM | <3.30.12 | |
Facebook HHVM | >=4.0.0<=4.8.5 | |
Facebook HHVM | >=4.9.0<=4.23.1 | |
Facebook HHVM | =4.24.0 | |
Facebook HHVM | =4.25.0 | |
Facebook HHVM | =4.26.0 | |
Facebook HHVM | =4.27.0 | |
Facebook HHVM | =4.28.0 | |
Facebook HHVM | =4.28.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11930 is critical with a score of 9.8 out of 10.
HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as versions 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1 are affected by CVE-2019-11930.
CVE-2019-11930 is an invalid free vulnerability in mb_detect_order that can cause the application to crash or potentially result in remote code execution.
To fix CVE-2019-11930, update HHVM to version 3.30.12 or later, 4.8.6 or later, 4.23.2 or later, or 4.29.0 or later.
More information about CVE-2019-11930 can be found at the following references: [GitHub Commit](https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36), [HHVM Security Update](https://hhvm.com/blog/2019/10/28/security-update.html), [Facebook Security Advisory](https://www.facebook.com/security/advisories/cve-2019-11930).