
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-1921 is a security vulnerability affecting HHVM (HipHop Virtual Machine) that involves an out-of-bounds write vulnerability in the crypt function. The vulnerability was discovered and disclosed in February 2021, affecting HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, and 4.98.0 (MITRE CVE, HHVM Blog).
The vulnerability exists in the crypt function where an attempt is made to null terminate a buffer using the size of the input salt without validating that the offset is within the buffer. This can lead to an out-of-bounds write condition of 1 byte (MITRE CVE, HHVM Blog).
The vulnerability could potentially allow an attacker to write outside the bounds of an allocated buffer, which could lead to memory corruption. This type of vulnerability can potentially be exploited to crash the application or execute arbitrary code (HHVM Blog).
While specific details about exploitation in the wild are not publicly available, the vulnerability requires the ability to control input to the crypt function to trigger the out-of-bounds write condition (MITRE CVE).
The vulnerability has been patched in HHVM versions 4.56.3, 4.80.2, 4.93.2, 4.94.1, 4.95.1, 4.96.1, 4.97.1, and 4.98.1. Users are advised to upgrade to one of these patched versions to protect against this vulnerability (HHVM Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."