cvedb.io
CVE-2019-3557
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2019-01-15T22:29:00.377 · Last modified 2026-06-17T02:35:13.447

Summary

The implementations of streams for bz2 and php://output improperly implemented their readImpl functions, returning -1 consistently. This behavior caused some stream functions, such as stream_get_line, to trigger an out-of-bounds read when operating on such malformed streams. The implementations were updated to return valid values consistently. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

Affected products

facebook — hhvm

Does this affect you?

Add your gear to cvedb and we'll alert you only when facebook ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.