CVE Vulnerabilities

CVE-2022-36937

Published: May 10, 2023 | Modified: Nov 07, 2023
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3.

Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected.

Affected Software

Name Vendor Start Version End Version
Hhvm Facebook * 4.153.4 (excluding)
Hhvm Facebook 4.154.0 (including) 4.168.2 (excluding)
Hhvm Facebook 4.169.0 (including) 4.169.2 (excluding)
Hhvm Facebook 4.170.0 (including) 4.170.2 (excluding)
Hhvm Facebook 4.171.0 (including) 4.171.0 (including)
Hhvm Facebook 4.172.0 (including) 4.172.0 (including)
Hhvm Ubuntu bionic *
Hhvm Ubuntu trusty *
Hhvm Ubuntu xenial *

References