CVE-2019-3556
Last modified
CVE-2019-3556 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
HHVM supports the use of an "admin" server which accepts administrative requests over HTTP. One of those request handlers, dump-pcre-cache, can be used to output cached regular expressions from the current execution context into a file. The handler takes a parameter which specifies where on the filesystem to write this data. The parameter is not validated, allowing a malicious user to overwrite arbitrary files where the user running HHVM has write access. This issue affects HHVM versions prior to 4.56.2, all versions between 4.57.0 and 4.78.0, as well as 4.79.0, 4.80.0, 4.81.0, 4.82.0, and 4.83.0.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hhvm | < 4.56.2 | |
| Hhvm | >= 4.57.0, <= 4.78.0 | |
| Hhvm | 4.79.0 | |
| Hhvm | 4.80.0 | |
| Hhvm | 4.81.0 | |
| Hhvm | 4.82.0 | |
| Hhvm | 4.83.0 |
References
- https://github.com/facebook/hhvm/commit/abe0b29e4d3a610f9bc920b8be4ad8403364c2d4Patch, Third Party Advisory
- https://hhvm.com/blog/2020/11/12/security-update.htmlVendor Advisory
- https://github.com/facebook/hhvm/commit/abe0b29e4d3a610f9bc920b8be4ad8403364c2d4Patch, Third Party Advisory
- https://hhvm.com/blog/2020/11/12/security-update.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3556?
How severe is CVE-2019-3556?
How do I fix CVE-2019-3556?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3498In Django 1.11.x before 1.11.18, 2.0.x before 2.0.10, and 2.…
- CVE-2019-3500aria2c in aria2 1.33.1, when --log is used, can store an HTT…7.8
- CVE-2019-3501The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via…
- CVE-2019-3552C++ Facebook Thrift servers (using cpp2) would not error upo…7.5
- CVE-2019-3553C++ Facebook Thrift servers would not error upon receiving m…7.5
- CVE-2019-3554Wangle's AcceptRoutingHandler incorrectly casts a socket whe…
- CVE-2019-3557The implementations of streams for bz2 and php://output impr…
- CVE-2019-3558Python Facebook Thrift servers would not error upon receivin…7.5
- CVE-2019-3559Java Facebook Thrift servers would not error upon receiving …7.5
- CVE-2019-3560An improperly performed length calculation on a buffer in Pl…7.5
- CVE-2019-3561Insufficient boundary checks for the strrpos and strripos fu…
- CVE-2019-3562A remote web page could inject arbitrary HTML code into the …
Are you affected by CVE-2019-3556?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
