CVE-2019-11935: Critical severity facebook hiphop virtual machine vulnerability
Insufficient boundary checks when processing a string in mberegreplace allows access to out-of-bounds memory. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11935?
The severity of CVE-2019-11935 is critical with a severity value of 9.8.
Which versions of HHVM are affected by CVE-2019-11935?
HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as versions 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1 are affected by CVE-2019-11935.
What is the vulnerability description of CVE-2019-11935?
CVE-2019-11935 is a vulnerability in HHVM that allows access to out-of-bounds memory due to insufficient boundary checks when processing a string in mb_ereg_replace.
How can I fix CVE-2019-11935?
To fix CVE-2019-11935, it is recommended to update HHVM to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-11935?
More information about CVE-2019-11935 can be found at the following references: [Link1], [Link2], [Link3].