Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27cx-293x-x7gq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

EPSS

Процентиль: 58%
0.00361
Низкий

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

CVSS3: 7.5
nvd
почти 5 лет назад

Incorrect bounds calculations in substr_compare could lead to an out-of-bounds read when the second string argument passed in is longer than the first. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0.

CVSS3: 7.5
debian
почти 5 лет назад

Incorrect bounds calculations in substr_compare could lead to an out-o ...

EPSS

Процентиль: 58%
0.00361
Низкий

Дефекты

CWE-125