René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

184 lines
6.1 KiB
JSON

{
"id": "CVE-2019-11929",
"sourceIdentifier": "cve-assign@fb.com",
"published": "2019-10-02T19:15:11.780",
"lastModified": "2019-10-10T17:14:58.233",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "Insufficient boundary checks when formatting numbers in number_format allows read/write access to out-of-bounds memory, potentially leading to remote code execution. This issue affects HHVM versions prior to 3.30.10, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.18.2, and versions 4.19.0, 4.19.1, 4.20.0, 4.20.1, 4.20.2, 4.21.0, 4.22.0, 4.23.0."
},
{
"lang": "es",
"value": "Las comprobaciones de l\u00edmites insuficientes cuando se formatea n\u00fameros en number_format permiten el acceso de lectura y escritura a la memoria fuera de l\u00edmites, conllevando potencialmente a la ejecuci\u00f3n remota de c\u00f3digo. Este problema afecta a HHVM versiones anteriores a 3.30.10, todas las versiones entre 4.0.0 y 4.8.5, todas las versiones entre 4.9.0 y 4.18.2, y las versiones 4.19.0, 4.19.1, 4.20.0, 4.20.1 , 4.20.2, 4.21.0, 4.22.0, 4.23.0."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
},
{
"source": "cve-assign@fb.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"versionEndExcluding": "3.30.10",
"matchCriteriaId": "F9AF3712-A1D5-46D5-984E-41F5DF38BE20"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.0.0",
"versionEndIncluding": "4.8.5",
"matchCriteriaId": "47FAA7FF-64A7-451F-A389-6CA4240D7871"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.9.0",
"versionEndIncluding": "4.18.2",
"matchCriteriaId": "EE55A7EC-B78A-401F-9F5C-9A89B7B0F30D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.19.0:*:*:*:*:*:*:*",
"matchCriteriaId": "6B376181-2C7E-4411-B2F6-B10F0D15973B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.19.1:*:*:*:*:*:*:*",
"matchCriteriaId": "2B5EDCE8-2484-422B-8D03-EF23B2303864"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.20.0:*:*:*:*:*:*:*",
"matchCriteriaId": "435AA02E-AECB-4C5F-AAC4-557A4F322AFA"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.20.1:*:*:*:*:*:*:*",
"matchCriteriaId": "4F48125F-9D5F-4E4F-B8A8-D3BAE29255C9"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.20.2:*:*:*:*:*:*:*",
"matchCriteriaId": "235460ED-9ACD-4252-B74D-4CE5744B005D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.21.0:*:*:*:*:*:*:*",
"matchCriteriaId": "7C48CF3C-CD59-4C10-8264-BFF5409245AE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.22.0:*:*:*:*:*:*:*",
"matchCriteriaId": "69E7E284-51AE-4F29-99BC-A3796F4C85D6"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:facebook:hhvm:4.23.0:*:*:*:*:*:*:*",
"matchCriteriaId": "E4F184AD-E91D-461B-B240-6C24504323A8"
}
]
}
]
}
],
"references": [
{
"url": "https://github.com/facebook/hhvm/commit/dbeb9a56a638e3fdcef8b691c2a2967132dae692",
"source": "cve-assign@fb.com",
"tags": [
"Patch",
"Third Party Advisory"
]
},
{
"url": "https://hhvm.com/blog/2019/09/25/security-update.html",
"source": "cve-assign@fb.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.facebook.com/security/advisories/cve-2019-11929",
"source": "cve-assign@fb.com",
"tags": [
"Third Party Advisory"
]
}
]
}