← volver
CVE-2020-1917

CVE-2020-1917

EPSS 1.4%CWE-122
Vexday Risk Score
3Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 mar 2021Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its standard append char function. As a result, if the buffer was full, it would result in an out-of-bounds write. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
Productos afectados
Facebook · HHVM

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →