CVE-2019-3557
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
Las implementaciones de los flujos para bz2 y php://output implementaron incorrectamente sus funciones readImpl, devolviendo -1 constantemente. Este comportamiento provocó que algunas funciones, como stream_get_line, desencadenasen una lectura fuera de límites al operar en tales flujos mal formados. Las implementaciones se actualizaron para que devuelvan valores válidos de forma consistente. Esto afecta a todas las versiones soportadas de HVVM (en versiones anteriores a las 3.30 y 3.27.4).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-02 CVE Reserved
- 2019-01-15 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/facebook/hhvm/commit/6e4dd9ec3f14b48170fc45dc9d13a3261765f994 | 2019-10-09 |
URL | Date | SRC |
---|---|---|
https://hhvm.com/blog/2019/01/14/hhvm-3.30.2.html | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Facebook Search vendor "Facebook" | Hhvm Search vendor "Facebook" for product "Hhvm" | <= 3.27.4 Search vendor "Facebook" for product "Hhvm" and version " <= 3.27.4" | - |
Affected
| ||||||
Facebook Search vendor "Facebook" | Hhvm Search vendor "Facebook" for product "Hhvm" | >= 3.28.0 <= 3.30.0 Search vendor "Facebook" for product "Hhvm" and version " >= 3.28.0 <= 3.30.0" | - |
Affected
|