An invalid free in mb_detect_order can cause the application to crash or potentially result in remote code execution. This issue affects HHVM versions prior to 3.30.12, all versions between 4.0.0 and 4.8.5, all versions between 4.9.0 and 4.23.1, as well as 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.28.0, and 4.28.1.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: facebook
Published: 2019-12-04T16:25:19
Updated: 2024-08-04T23:10:29.455Z
Reserved: 2019-05-13T00:00:00
Link: CVE-2019-11930
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-12-04T17:16:43.087
Modified: 2024-11-21T04:22:00.307
Link: CVE-2019-11930
Redhat
No data.