Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: facebook

Published: 2021-03-10T15:50:30

Updated: 2024-08-03T19:14:10.116Z

Reserved: 2021-01-13T00:00:00

Link: CVE-2021-24025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-10T16:15:16.750

Modified: 2024-11-21T05:52:14.053

Link: CVE-2021-24025

cve-icon Redhat

No data.