Vulnerability Description
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hiphop Virtual Machine | <= 2.4.1 |
Related Weaknesses (CWE)
References
- https://github.com/facebook/hhvm/commit/506a44194a9016406c752ad8e010c01aeffc18cc
- https://github.com/facebook/hhvm/commit/506a44194a9016406c752ad8e010c01aeffc18cc
FAQ
What is CVE-2014-2208?
CVE-2014-2208 is a vulnerability with a CVSS score of 7.5 (HIGH). CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitr...
How severe is CVE-2014-2208?
CVE-2014-2208 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-2208?
Check the references section above for vendor advisories and patch information. Affected products include: Facebook Hiphop Virtual Machine.