CVE-2019-3557
Last modified
CVE-2019-3557 is a vulnerability of currently unknown severity. The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. EPSS estimates a 1.71% chance of exploitation in the next 30 days.
Description
The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hhvm | <= 3.27.4 | |
| Hhvm | >= 3.28.0, <= 3.30.0 |
References
- https://github.com/facebook/hhvm/commit/6e4dd9ec3f14b48170fc45dc9d13a3261765f994Patch, Third Party Advisory
- https://hhvm.com/blog/2019/01/14/hhvm-3.30.2.htmlVendor Advisory
- https://github.com/facebook/hhvm/commit/6e4dd9ec3f14b48170fc45dc9d13a3261765f994Patch, Third Party Advisory
- https://hhvm.com/blog/2019/01/14/hhvm-3.30.2.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3557?
How severe is CVE-2019-3557?
How do I fix CVE-2019-3557?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3500aria2c in aria2 1.33.1, when --log is used, can store an HTT…7.8
- CVE-2019-3501The OUGC Awards plugin before 1.8.19 for MyBB allows XSS via…
- CVE-2019-3552C++ Facebook Thrift servers (using cpp2) would not error upo…7.5
- CVE-2019-3553C++ Facebook Thrift servers would not error upon receiving m…7.5
- CVE-2019-3554Wangle's AcceptRoutingHandler incorrectly casts a socket whe…
- CVE-2019-3556HHVM supports the use of an "admin" server which accepts adm…8.1
- CVE-2019-3558Python Facebook Thrift servers would not error upon receivin…7.5
- CVE-2019-3559Java Facebook Thrift servers would not error upon receiving …7.5
- CVE-2019-3560An improperly performed length calculation on a buffer in Pl…7.5
- CVE-2019-3561Insufficient boundary checks for the strrpos and strripos fu…
- CVE-2019-3562A remote web page could inject arbitrary HTML code into the …
- CVE-2019-3563Wangle's LineBasedFrameDecoder contains logic for identifyin…9.8
Are you affected by CVE-2019-3557?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
