Out-of-bounds write in the (1) mb_detect_encoding, (2) mb_send_mail, and (3) mb_detect_order functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2016/08/11/1 | mailing list third party advisory patch |
https://github.com/facebook/hhvm/commit/365abe807cab2d60dc9ec307292a06181f77a9c2 | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2016/08/19/1 | mailing list third party advisory patch |