CVE-2020-1919: High severity facebook hiphop virtual machine vulnerability
Incorrect bounds calculations in substrcompare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-1919.
What is the severity of CVE-2020-1919?
The severity of CVE-2020-1919 is high, with a severity value of 7.5.
Which software versions are affected by CVE-2020-1919?
CVE-2020-1919 affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, and 4.98.0.
How does CVE-2020-1919 occur?
CVE-2020-1919 occurs due to incorrect bounds calculations in the substr_compare function, leading to an out-of-bounds read when the second string argument passed in is longer than the first.
How can I fix CVE-2020-1919?
To fix CVE-2020-1919, it is recommended to update HHVM to a version that is not affected by the vulnerability.