« Volver al listado

CVE-2020-1916

Estado: ModificadaCrítica (9.8)—

An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all versions between 4.57.0 and 4.78.0, 4.79.0, 4.80.0, 4.81.0, 4.82.0, 4.83.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-1916",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Facebook",
          "product": "HHVM",
          "versions": [
            {
              "status": "unaffected",
              "version": "4.83.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.83.0"
            },
            {
              "status": "unaffected",
              "version": "4.82.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.82.0"
            },
            {
              "status": "unaffected",
              "version": "4.81.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.81.0"
            },
            {
              "status": "unaffected",
              "version": "4.80.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.80.0"
            },
            {
              "status": "unaffected",
              "version": "4.79.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.79.0"
            },
            {
              "status": "unaffected",
              "version": "4.78.1",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "4.57.0",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "unaffected",
              "version": "4.56.2",
              "lessThan": "unspecified",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "4.56.2",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-03-10T16:15:14.173",
  "references": [
    {
      "url": "https://github.com/facebook/hhvm/commit/abe0b29e4d3a610f9bc920b8be4ad8403364c2d4",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://hhvm.com/blog/2020/11/12/security-update.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://github.com/facebook/hhvm/commit/abe0b29e4d3a610f9bc920b8be4ad8403364c2d4",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://hhvm.com/blog/2020/11/12/security-update.html",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-assign@fb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-787"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An incorrect size calculation in ldap_escape may lead to an integer overflow when overly long input is passed in, resulting in an out-of-bounds write. This issue affects HHVM prior to 4.56.2, all versions between 4.57.0 and 4.78.0, 4.79.0, 4.80.0, 4.81.0, 4.82.0, 4.83.0."
    },
    {
      "lang": "es",
      "value": "Un cálculo de tamaño incorrecto en la función ldap_escape puede conllevar a un desbordamiento de enteros cuando es pasada una entrada demasiado larga, resultando en una escritura fuera de límites. Este problema afecta a HHVM versiones anteriores a 4.56.2, todas las versiones entre 4.57.0 y 4.78.0, 4.79.0, 4.80.0, 4.81.0, 4.82.0, 4.83.0"
    }
  ],
  "lastModified": "2026-06-17T03:02:36.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6711FFC9-F4D3-438B-B596-30FCB4EAF015",
              "versionEndExcluding": "4.56.2"
            },
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14D6DF29-4414-4A07-99E9-1BD568EC77A7",
              "versionEndExcluding": "4.78.1",
              "versionStartIncluding": "4.57.0"
            },
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:4.79.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C83AAFF-2886-424B-A9BD-251B3AAC790B"
            },
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:4.80.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73B27B4A-CD40-4493-BDCD-27F6ADD6C65A"
            },
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:4.81.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BD9447B-B287-484B-A14C-787F8481EBB8"
            },
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:4.82.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15825F25-22B8-4863-A4E0-AD2EE66FA12C"
            },
            {
              "criteria": "cpe:2.3:a:facebook:hhvm:4.83.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A04923E1-4DCE-4E34-8238-99BCCEEF4791"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}