Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HFacebook Folly
APPFacebook< 2021.07.22.00Facebook Hhvm
APPFacebook4.114.04.115.04.116.04.117.04.118.04.118.14.81.0 – 4.102.1< 4.80.54.103.0 – 4.113.0
Related vulnerabilities
HHVM: użycie przestarzałego protokołu TLS 1.0 zamiast TLS 1.3
Use-after-free w Facebook HHVM podczas deserializacji obiektów z dynamicznymi właściwościami
Integer overflow w preg_quote HHVM prowadzący do heap overflow (RCE)
Integer overflow i out-of-bounds write w funkcji ldap_escape HHVM
Out-of-bounds write w HHVM podczas przetwarzania danych EXIF