Out-of-Bounds Read Vulnerability in Memcache::getextendedstats Function in HHVM

Out-of-Bounds Read Vulnerability in Memcache::getextendedstats Function in HHVM

CVE-2018-6340 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

Learn more about our Cis Benchmark Audit For Server Software.