V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2019-11936
DEB
Critical

Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM version…

CVSS
9.8
Critical
EPSS
0.01
p70
Published
2019-01-01
Updated
2019-01-01
Description

Various APC functions accept keys containing null bytes as input, leading to premature truncation of input. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.

Tags · CWE
Pre-auth
CWE-626
Affected products
Hhvm < 3.30.12Hhvm 4.0.0–4.8.5Hhvm 4.9.0–4.23.1Hhvm
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.015 · p70
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
hhvmTracked
hhvmTracked
hhvmTracked
hhvmTracked
hhvm*Tracked
Source databases
DEB
CVE
UBU