TROYANOSYVIRUS
Back to CVEs

CVE-2020-1898

HIGH
7.5

Description

The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to recurse, leading to stack exhaustion. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

CVE Details

CVSS v3.1 Score7.5
SeverityHIGH
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published3/11/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

facebook:hhvm

Weaknesses (CWE)

CWE-674CWE-674

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.