CVE-2020-1892: High severity Facebook HHVM vulnerability
Published Mar 3, 2020
·Updated
Insufficient boundary checks when decoding JSON in JSONparser allows read access to out of bounds memory, potentially leading to information leak and DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive), versions between 4.9.0 and 4.32.0 (inclusive), and versions prior to 4.8.7.
Affected Software
10 affected components
Facebook HHVM<4.8.7
Facebook HHVM>=4.9.0<=4.32.0
Facebook HHVM>=4.33.0<=4.38.0
Facebook HHVM=4.39.0
Facebook HHVM=4.40.0
Facebook HHVM=4.41.0
Facebook HHVM=4.42.0
Facebook HHVM=4.43.0
Facebook HHVM=4.44.0
Facebook HHVM=4.45.0
Event History
Mar 3, 2020
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
CVE-2020-1892
2
What is the severity of CVE-2020-1892?
The severity of CVE-2020-1892 is high with a CVSS score of 8.1.
3
Which software versions are affected by CVE-2020-1892?
CVE-2020-1892 affects versions of HHVM between 4.33.0 and 4.45.0 (inclusive).
4
What are the potential impacts of CVE-2020-1892?
CVE-2020-1892 can lead to information leakage and denial of service (DOS) attacks.
5
Are there any patches or fixes available for CVE-2020-1892?
Yes, patches and updates are available to address the vulnerability. Please refer to the vendor's website for more information.