CVE-2019-11936: Critical severity facebook hiphop virtual machine vulnerability
Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11936?
CVE-2019-11936 is a vulnerability in various APC functions in Facebook HHVM that accept keys containing null bytes as input, leading to premature truncation of input.
What is the severity of CVE-2019-11936?
CVE-2019-11936 has a severity rating of 9.8 (critical).
Which versions of HHVM are affected by CVE-2019-11936?
HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as versions 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1 are affected by CVE-2019-11936.
How do I fix CVE-2019-11936?
To fix CVE-2019-11936, it is recommended to upgrade HHVM to version 4.23.1 or above.
Where can I find more information about CVE-2019-11936?
You can find more information about CVE-2019-11936 on the Github commit, the HHVM blog post, and the Facebook security advisory.