The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published: 2018-12-31T22:00:00

Updated: 2024-08-05T06:01:48.705Z

Reserved: 2018-01-26T00:00:00

Link: CVE-2018-6340

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-12-31T22:29:00.327

Modified: 2019-10-09T23:41:46.970

Link: CVE-2018-6340

cve-icon Redhat

No data.