CVE-2019-3557
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 co
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently.
This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
CRITICAL · CVSS 9.8
EPSS 0.00746
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0