Get a Pentest and security assessment of your IT network.

2021-current

CVE-2020-1899 – The unserialize() function supported a type code, “S”, which was meant to

The unserialize() function supported a type code, “S”, which was meant to be supported only for APC serialization. This type code allowed arbitrary memory addresses to be accessed as if they were static StringData objects. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1899

Reference (s):

  • https://hhvm.com/blog/2020/06/30/security-update.html
  • URL: https://hhvm.com/blog/2020/06/30/security-update.html
  • https://github.com/facebook/hhvm/commit/1107228a5128d3ca1c4add8ac1635d933cbbe2e9
  • URL: https://github.com/facebook/hhvm/commit/1107228a5128d3ca1c4add8ac1635d933cbbe2e9
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-5418 - GE Multilink ML800, ML1200, ML1600, and ML2400 switches with firmware 4.2

2021-current

CVE-2019-7127 - Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20

2021-current

CVE-2020-10978 - GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a pu