En

HHVM官网安全更新(2021-02-25)

来源:HHVM官网 发布日期:2021-02-25 阅读次数:7017 评论:0

基本信息

发布日期:2021-02-25(官方当地时间)

更新类型:安全更新

更新版本:4.56.3

感知时间:2021-02-26 07:54:13

风险等级:未知

情报贡献:TSRC

更新标题

安全更新

更新详情

A security update has been released for all supported HHVM versions. Please
update to one of the following versions to make sure you’re secure: 4.56.3
4.80.2
4.93.2
4.94.1
4.95.1
4.96.1
4.97.1
4.98.1This security update addresses the following vulnerabilities: CVE-2020-1917:
out-of-bounds write (1 byte) in exif_read_data()
CVE-2020-1918:
memory disclosure vulnerability using “data:” URLs
CVE-2020-1919:
out-of-bounds heap read in substr_compare()
CVE-2020-1921:
out-of-bounds write (1 byte) in crypt()
CVE-2021-24025:
integer overflow causing out-of-bounds heap write in preg_quote()
out-of-bounds heap read (2 bytes) in exif_read_data()

软件描述

HHVM (HipHop Virtual Machine)会将PHP代码转换成高级别的字节码(通常称为中间语言)。然后在运行时通过即时(JIT)编译器将这些字节码转换为x64的机器码

TSRC分析

暂无

业界资讯

暂无

评论

提交评论 您输入的评论有误,请重新输入