Candidate: CVE-2018-6335 PublicDate: 2018-12-31 19:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-6335 https://hhvm.com/blog/2018/05/04/hhvm-3.25.3.html Description: A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, and 3.21.10 and below) when using the proxygen server to handle HTTP2 requests. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H [7.5 HIGH] Patches_hhvm: upstream: https://github.com/facebook/hhvm/commit/4cb57dd753a339654ca464c139db9871fe961d56 upstream_hhvm: released (3.24.7+dfsg-1) precise/esm_hhvm: DNE trusty_hhvm: DNE trusty/esm_hhvm: DNE xenial_hhvm: ignored (end of standard support, was needs-triage) artful_hhvm: ignored (reached end-of-life) bionic_hhvm: needs-triage cosmic_hhvm: DNE disco_hhvm: DNE eoan_hhvm: DNE focal_hhvm: DNE groovy_hhvm: DNE hirsute_hhvm: DNE impish_hhvm: DNE jammy_hhvm: DNE devel_hhvm: DNE