CRITICAL
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution
Published Dec 4, 2019
9.8
CRITICALCVSS 3.1
EPSS 3.25%
Description
An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Affected products
-
Affected
- 3.30.12
- ≥ 4.0.0, < unspecified
- 4.23.2
- ≥ 4.24.0, < unspecified
- 4.24.1
- ≥ 4.25.0, < unspecified
- 4.25.1
- ≥ 4.26.0, < unspecified
- 4.26.1
- ≥ 4.27.0, < unspecified
- 4.27.1
- ≥ 4.28.0, < unspecified
- 4.28.2
- 4.8.6
- ≥ 4.9.0, < unspecified
- ≥ unspecified, < 3.30.12
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| HHVM | unknown | Affected
|
OR
- < 3.30.12
- ≥ 4.0.0 · ≤ 4.8.5
- ≥ 4.9.0 · ≤ 4.23.1
- 4.24.0
- 4.25.0
- 4.26.0
- 4.27.0
- 4.28.0
- 4.28.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3588 Advisory
- https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36 x_refsource_CONFIRMPatch
- https://hhvm.com/blog/2019/10/28/security-update.html x_refsource_CONFIRMVendor Advisory
- https://www.facebook.com/security/advisories/cve-2019-11930 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3588 | Advisory | |
| https://github.com/facebook/hhvm/commit/524d2e60cfe910406ec6109e4286d7edd545ab36 | x_refsource_CONFIRMPatch | |
| https://hhvm.com/blog/2019/10/28/security-update.html | x_refsource_CONFIRMVendor Advisory | |
| https://www.facebook.com/security/advisories/cve-2019-11930 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner facebook
Published Dec 4, 2019
Updated Aug 4, 2024
Reserved May 13, 2019
Link CVE-2019-11930
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data