CVE-2021-24036
Published: Jul 23, 2021
Modified: Aug 3, 2024
Description
Passing an attacker controlled size when creating an IOBuf could cause integer overflow, leading to an out of bounds write on the heap with the possibility of remote code execution. This issue affects versions of folly prior to v2021.07.22.00. This issue affects HHVM versions prior to 4.80.5, all versions between 4.81.0 and 4.102.1, all versions between 4.103.0 and 4.113.0, and versions 4.114.0, 4.115.0, 4.116.0, 4.117.0, 4.118.0 and 4.118.1.
| Vendor | Product | Versions |
|---|---|---|
folly | unaffected v2021.07.22.00 - < unspecifiedaffected unspecified - < v2021.07.22.00 | |
HHVM | unaffected 4.118.2 - < unspecifiedaffected 4.118.0 - < unspecifiedunaffected 4.117.1 - < unspecifiedaffected 4.117.0unaffected 4.116.1 - < unspecified+12 more versions |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now