CVE-2019-11929
high-risk
Published 2019-10-02
Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.
Do I need to act?
~
4.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 6870c5d6361293a6eccc0e1746cf03cb62faad5f, dbeb9a56a638e3fdcef8b691c2a2967132dae692
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Vendors
References (6)
Vendor Advisory
https://hhvm.com/blog/2019/09/25/security-update.html
Third Party Advisory
https://www.facebook.com/security/advisories/cve-2019-11929
Vendor Advisory
https://hhvm.com/blog/2019/09/25/security-update.html
Third Party Advisory
https://www.facebook.com/security/advisories/cve-2019-11929
55
/ 100
high-risk
Severity
32/34 · Critical
Exploitability
8/34 · Low
Exposure
15/34 · Moderate