← voltar
CVE-2020-1917

CVE-2020-1917

EPSS 1.4%CWE-122
Vexday Risk Score
3Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS EPSS 1.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
10 mar 2021Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
xbuf_format_converter, used as part of exif_read_data, was appending a terminating null character to the generated string, but was not using its standard append char function. As a result, if the buffer was full, it would result in an out-of-bounds write. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.
Produtos afetados
Facebook · HHVM

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →