CVE-2019-11929

high-risk
Published 2019-10-02

Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0.

Do I need to act?

~
4.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
+
Fix available
Upgrade to: 6870c5d6361293a6eccc0e1746cf03cb62faad5f, dbeb9a56a638e3fdcef8b691c2a2967132dae692
9
CVSS 9.8/10 Critical
NETWORK / LOW complexity

Affected Products (9)

Affected Vendors

55
/ 100
high-risk
Severity 32/34 · Critical
Exploitability 8/34 · Low
Exposure 15/34 · Moderate