CVE-2020-1888 (NVD)

2020-03-03

Insufficient boundary checks when decoding JSON in handleBackslash reads out of bounds memory, potentially leading to DOS. This issue affects HHVM 4.45.0, 4.44.0, 4.43.0, 4.42.0, 4.41.0, 4.40.0, 4.39.0, versions between 4.33.0 and 4.38.0 (inclusive), versions between 4.9.0 and 4.32.0 (inclusive), and versions prior to 4.8.7.

Products Hhvm
Type Out-of-bounds Read (CWE-125)
First patch - None (likely due to unavailable code)
Links https://github.com/facebook/hhvm/commit/b3679121bb3c7017ff04b4c08402ffff5cf59b13
https://hhvm.com/blog/2020/02/20/security-update.html