| Title | HHVM における再帰制御に関する脆弱性 |
|---|---|
| Summary | HHVM には、再帰制御に関する脆弱性が存在します。 |
| Possible impacts | サービス運用妨害 (DoS) 状態にされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | June 30, 2020, midnight |
| Registration Date | Nov. 19, 2021, 6:03 p.m. |
| Last Update | Nov. 19, 2021, 6:03 p.m. |
| CVSS3.0 : 重要 | |
| Score | 7.5 |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS2.0 : 警告 | |
| Score | 5 |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| HipHop Virtual Machine (HHVM) 4.32.3 未満 |
| HipHop Virtual Machine (HHVM) 4.33.0 から 4.56.0 |
| HipHop Virtual Machine (HHVM) 4.57.0 |
| HipHop Virtual Machine (HHVM) 4.58.0 |
| HipHop Virtual Machine (HHVM) 4.58.1 |
| HipHop Virtual Machine (HHVM) 4.59.0 |
| HipHop Virtual Machine (HHVM) 4.60.0 |
| HipHop Virtual Machine (HHVM) 4.61.0 |
| HipHop Virtual Machine (HHVM) 4.62.0 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2021年11月19日] 掲載 |
Nov. 19, 2021, 6:03 p.m. |
| Summary | The fb_unserialize function did not impose a depth limit for nested deserialization. That meant a maliciously constructed string could cause deserialization to recurse, leading to stack exhaustion. This issue affected HHVM prior to v4.32.3, between versions 4.33.0 and 4.56.0, 4.57.0, 4.58.0, 4.58.1, 4.59.0, 4.60.0, 4.61.0, 4.62.0. |
|---|---|
| Publication Date | March 11, 2021, 10:15 a.m. |
| Registration Date | March 11, 2021, 4 p.m. |
| Last Update | Nov. 21, 2024, 2:11 p.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:facebook:hhvm:4.58.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:4.58.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:4.59.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:4.60.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:4.61.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:4.62.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:4.57.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* | 4.33.0 | 4.56.1 | |||
| cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:* | 4.32.3 | ||||