← Retour aux CVEs
CVE-2018-6337
HIGH7.5
Description
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.
Details CVE
Score CVSS v3.17.5
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie12/31/2018
Derniere modification5/6/2025
Sourcenvd
Observations honeypot0
Produits affectes
facebook:follyfacebook:hhvm
Faiblesses (CWE)
CWE-212CWE-119
References
https://github.com/facebook/folly/commit/8e927ee48b114c8a2f90d0cbd5ac753795a6761f(cve-assign@fb.com)
https://hhvm.com/blog/2018/05/24/hhvm-3.26.3.html(cve-assign@fb.com)
https://github.com/facebook/folly/commit/8e927ee48b114c8a2f90d0cbd5ac753795a6761f(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/facebook/hhvm/commit/e2d10a1e32d01f71aaadd81169bcb9ae86c5d6b8(af854a3a-2127-422b-91ae-364da2661108)
https://hhvm.com/blog/2018/05/24/hhvm-3.26.3.html(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.