CVE Vulnerabilities

CVE-2016-1000004

Insufficient Verification of Data Authenticity

Published: Feb 19, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
HhvmFacebook*3.9.5 (excluding)
HhvmFacebook3.10.0 (including)3.12.3 (including)
HhvmFacebook3.13.0 (including)3.14.1 (including)
HhvmUbuntuesm-apps/xenial*
HhvmUbuntuupstream*
HhvmUbuntuxenial*

References