VDB
CVE-2019-3557
CVE-2019-3557
PUBLISHED
CVSS 9.800000190734863 CRITICAL
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
EPSS 1.54% · 72.8th percentile
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
1.54%
72.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:16.04:LTS | hhvm | 0, 3.11.0+dfsg-1, 3.11.1+dfsg-1 |
| Ubuntu:18.04:LTS | hhvm | *, 0, * |
Timeline
- Jan 15, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-3557 third-party-advisory
- https://github.com/facebook/hhvm/commit/6e4dd9ec3f14b48170fc45dc9d13a3261765f994 third-party-advisory
- https://hhvm.com/blog/2019/01/14/hhvm-3.30.2.html third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-3557 third-party-advisory