CVE-2018-6340

The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported versions of HHVM (3.30 and 3.27.4 and below).

packagechannelchannel versionpkg versionstatus
hhvm
nixos-18.03
2019-02-20 10:25:14 UTC (cb0e20)3.23.2vulnerable
2019-01-16 18:00:31 UTC (138f2c)3.23.2vulnerable
2018-12-09 06:05:37 UTC (b551f8)3.23.2vulnerable
2018-11-29 21:00:31 UTC (a18112)3.23.2vulnerable
2018-11-28 06:10:25 UTC (9c96d1)3.23.2vulnerable
2018-11-23 12:45:42 UTC (e64482)3.23.2vulnerable
2018-11-20 12:35:27 UTC (947247)3.23.2vulnerable
2018-11-16 21:00:27 UTC (263f7b)3.23.2vulnerable
2018-11-14 10:35:19 UTC (1d8470)3.23.2vulnerable
2018-11-05 13:10:34 UTC (21b7f5)3.23.2vulnerable
2018-11-02 08:50:28 UTC (0e614d)3.23.2vulnerable
2018-10-30 16:25:07 UTC (19fc6d)3.23.2vulnerable
2018-10-30 14:40:31 UTC (6f07d2)3.23.2vulnerable
2018-10-28 11:35:42 UTC (b4e3a4)3.23.2vulnerable
2018-10-15 12:50:34 UTC (5d19e3)3.23.2vulnerable
2018-10-13 20:20:17 UTC (e85e0c)3.23.2vulnerable
2018-10-13 09:40:17 UTC (d592f2)3.23.2vulnerable
2018-10-11 15:15:08 UTC (5a38f7)3.23.2vulnerable
2018-10-09 11:20:30 UTC (c56ede)3.23.2vulnerable
2018-10-05 13:25:12 UTC (862fb5)3.23.2vulnerable
2018-10-05 13:00:32 UTC (c4eddc)3.23.2vulnerable
2018-09-21 06:10:31 UTC (d16a7a)3.23.2vulnerable
2018-09-19 17:10:27 UTC (8edf56)3.23.2vulnerable
2018-09-18 17:55:38 UTC (305f13)3.23.2vulnerable
2018-09-16 07:30:36 UTC (01f5e7)3.23.2vulnerable
2018-09-13 15:30:12 UTC (5f59ab)3.23.2vulnerable
2018-09-08 09:20:09 UTC (45f52f)3.23.2vulnerable
2018-09-02 21:10:32 UTC (8b92a4)3.23.2vulnerable
2018-09-02 14:20:10 UTC (8c172c)3.23.2vulnerable
2018-09-01 13:55:20 UTC (a960b8)3.23.2vulnerable
2018-08-31 04:20:38 UTC (a37638)3.23.2vulnerable
2018-08-29 17:10:10 UTC (edd63e)3.23.2vulnerable
2018-08-24 19:10:30 UTC (fde201)3.23.2vulnerable
2018-08-23 23:50:20 UTC (f094fd)3.23.2vulnerable
2018-08-19 18:15:22 UTC (4df342)3.23.2vulnerable
2018-08-18 23:45:22 UTC (47b68d)3.23.2vulnerable
2018-08-17 21:25:22 UTC (a4e068)3.23.2vulnerable
2018-08-17 14:30:05 UTC (cd0cd9)3.23.2vulnerable
2018-08-16 13:20:15 UTC (c1ef96)3.23.2vulnerable
2018-08-16 08:30:34 UTC (8b4ed6)3.23.2vulnerable
2018-08-15 15:40:37 UTC (5b8a24)3.23.2vulnerable
2018-08-15 05:50:22 UTC (66bd47)3.23.2vulnerable
2018-08-14 17:35:19 UTC (9cbc73)3.23.2vulnerable
2018-08-13 09:25:26 UTC (10b979)3.23.2vulnerable
2018-08-13 03:20:34 UTC (89ff9f)3.23.2vulnerable
2018-08-12 04:35:15 UTC (bfeab2)3.23.2vulnerable
2018-08-12 00:00:33 UTC (190ec7)3.23.2vulnerable
2018-08-10 22:20:22 UTC (e42c07)3.23.2vulnerable
2018-08-10 17:05:22 UTC (2c3f9c)3.23.2vulnerable
2018-08-09 21:05:22 UTC (3af001)3.23.2vulnerable
2018-08-07 05:10:16 UTC (230f98)3.23.2vulnerable
2018-08-03 03:05:12 UTC (d0c868)3.23.2vulnerable
2018-08-02 12:45:41 UTC (18401b)3.23.2vulnerable
2018-08-02 06:10:24 UTC (0e55dd)3.23.2vulnerable
2018-08-01 00:55:32 UTC (a1299c)3.23.2vulnerable
2018-07-31 16:00:28 UTC (b74b1c)3.23.2vulnerable
2018-07-30 09:15:16 UTC (6115f4)3.23.2vulnerable
2018-07-20 17:40:08 UTC (d6c6c7)3.23.2vulnerable
2018-07-12 04:35:08 UTC (411cc5)3.23.2vulnerable
2018-07-10 08:10:12 UTC (aec217)3.23.2vulnerable
2018-07-10 03:15:29 UTC (5e10df)3.23.2vulnerable
2018-07-09 02:40:20 UTC (e930c6)3.23.2vulnerable
2018-07-08 17:55:36 UTC (de7ca4)3.23.2vulnerable
2018-07-08 10:25:33 UTC (298e17)3.23.2vulnerable
2018-07-04 20:00:25 UTC (56fad1)3.23.2vulnerable
2018-06-30 13:55:14 UTC (2f06e0)3.23.2vulnerable
2018-06-29 17:10:06 UTC (0a70d6)3.23.2vulnerable
2018-06-25 10:30:35 UTC (94d80e)3.23.2vulnerable
2018-06-23 08:30:21 UTC (91b286)3.23.2vulnerable
2018-06-21 23:25:24 UTC (68e02f)3.23.2vulnerable
2018-06-17 01:05:39 UTC (14c248)3.23.2vulnerable
2018-06-16 09:40:33 UTC (f3c913)3.23.2vulnerable
2018-06-14 21:57:20 UTC (08d245)3.23.2vulnerable
nixos-19.03
2019-05-20 19:26:33 UTC (cdec62)3.23.2vulnerable
2019-05-19 05:45:38 UTC (705986)3.23.2vulnerable
2019-05-18 19:20:38 UTC (cff736)3.23.2vulnerable
2019-05-18 14:40:37 UTC (51cc0e)3.23.2vulnerable
2019-05-18 12:10:29 UTC (c86f09)3.23.2vulnerable
2019-05-16 07:25:27 UTC (c21f08)3.23.2vulnerable
2019-05-15 23:05:36 UTC (f5493b)3.23.2vulnerable
2019-05-14 10:50:48 UTC (7cd2e4)3.23.2vulnerable
2019-05-14 04:40:47 UTC (af657b)3.23.2vulnerable
2019-05-12 22:55:17 UTC (727e5b)3.23.2vulnerable
2019-05-12 18:15:28 UTC (c2570e)3.23.2vulnerable
2019-05-12 06:15:30 UTC (312a05)3.23.2vulnerable
2019-05-10 05:55:42 UTC (7bb74e)3.23.2vulnerable
2019-05-09 23:45:28 UTC (2ec36d)3.23.2vulnerable
2019-05-09 11:30:25 UTC (096e2f)3.23.2vulnerable
2019-05-08 07:05:44 UTC (aade6d)3.23.2vulnerable
2019-05-08 03:25:43 UTC (a04ef7)3.23.2vulnerable
2019-05-07 18:25:28 UTC (3e7300)3.23.2vulnerable
2019-05-07 12:25:52 UTC (2dcbd4)3.23.2vulnerable
2019-05-07 03:45:44 UTC (2df17e)3.23.2vulnerable
2019-05-06 22:45:43 UTC (8c6c85)3.23.2vulnerable
2019-05-06 19:05:39 UTC (6ec097)3.23.2vulnerable
2019-05-05 20:50:42 UTC (a177da)3.23.2vulnerable
2019-05-05 11:55:39 UTC (6e29f2)3.23.2vulnerable
2019-05-05 08:25:33 UTC (04954e)3.23.2vulnerable
2019-05-02 22:00:31 UTC (915ce0)3.23.2vulnerable
2019-05-02 14:05:46 UTC (2e6afa)3.23.2vulnerable
2019-05-02 10:40:42 UTC (b2b5c1)3.23.2vulnerable
2019-05-01 17:25:26 UTC (d740b2)3.23.2vulnerable
2019-04-30 23:15:17 UTC (6d7ed9)3.23.2vulnerable
2019-04-25 16:05:41 UTC (cf3e27)3.23.2vulnerable
2019-04-24 14:30:20 UTC (2f1eac)3.23.2vulnerable
2019-04-24 10:40:27 UTC (893541)3.23.2vulnerable
2019-04-23 19:20:27 UTC (793640)3.23.2vulnerable
2019-04-22 06:20:19 UTC (330b9f)3.23.2vulnerable
2019-04-21 17:40:24 UTC (454eea)3.23.2vulnerable
2019-04-21 16:40:14 UTC (83e778)3.23.2vulnerable
2019-04-21 10:05:20 UTC (73c885)3.23.2vulnerable
2019-04-20 19:45:16 UTC (b807bc)3.23.2vulnerable
2019-04-19 19:40:31 UTC (8ea36d)3.23.2vulnerable
2019-04-17 11:30:25 UTC (7b3696)3.23.2vulnerable
2019-04-16 15:30:40 UTC (ea4979)3.23.2vulnerable
2019-04-10 15:10:50 UTC (5c52b2)3.23.2vulnerable
2019-04-10 14:15:29 UTC (63f250)3.23.2vulnerable
2019-04-10 10:35:28 UTC (f52505)3.23.2vulnerable
2019-04-10 08:25:33 UTC (0363ab)3.23.2vulnerable
2019-04-08 01:00:36 UTC (67bc63)3.23.2vulnerable
2019-04-05 01:55:19 UTC (91fa69)3.23.2vulnerable
2019-04-04 23:20:18 UTC (e18a58)3.23.2vulnerable
2019-04-04 17:35:16 UTC (ef2899)3.23.2vulnerable
2019-03-31 05:55:25 UTC (3a4ffd)3.23.2vulnerable
2019-03-25 19:05:29 UTC (23fd13)3.23.2vulnerable
2019-03-24 15:55:20 UTC (ff9c3f)3.23.2vulnerable
2019-03-24 09:05:37 UTC (fe9abc)3.23.2vulnerable
2019-03-23 20:25:30 UTC (638216)3.23.2vulnerable
2019-03-22 23:55:24 UTC (f5e7da)3.23.2vulnerable
2019-03-21 04:35:34 UTC (91cb80)3.23.2vulnerable
2019-03-20 11:55:29 UTC (3574db)3.23.2vulnerable
2019-03-19 17:15:39 UTC (f00bd2)3.23.2vulnerable
2019-03-19 13:55:38 UTC (2a7c34)3.23.2vulnerable
2019-03-19 04:40:34 UTC (e0e29a)3.23.2vulnerable
2019-03-18 08:30:37 UTC (b2b2ff)3.23.2vulnerable
2019-03-18 07:25:46 UTC (6a3a05)3.23.2vulnerable
2019-03-17 11:45:18 UTC (9aab14)3.23.2vulnerable
2019-03-16 16:45:40 UTC (aa34ca)3.23.2vulnerable
2019-03-11 16:05:16 UTC (5f3be9)3.23.2vulnerable
2019-03-11 11:05:32 UTC (aea913)3.23.2vulnerable
2019-03-11 04:15:21 UTC (508764)3.23.2vulnerable
2019-03-10 20:35:28 UTC (72ad05)3.23.2vulnerable
2019-03-10 14:30:29 UTC (360522)3.23.2vulnerable
2019-03-10 03:10:39 UTC (52565a)3.23.2vulnerable
2019-03-10 02:25:21 UTC (4610d6)3.23.2vulnerable
2019-03-08 17:55:42 UTC (584748)3.23.2vulnerable
2019-03-07 03:15:40 UTC (58e31b)3.23.2vulnerable
2019-02-26 20:35:21 UTC (07e2b5)3.23.2vulnerable
nixos-unstable
2019-05-03 17:40:38 UTC (190727)3.23.2vulnerable
2019-04-30 23:35:46 UTC (aeb464)3.23.2vulnerable
2019-04-25 16:30:32 UTC (dfd8f8)3.23.2vulnerable
2019-04-24 12:55:41 UTC (0620e0)3.23.2vulnerable
2019-04-21 22:55:37 UTC (d26027)3.23.2vulnerable
2019-04-16 15:55:38 UTC (1fc591)3.23.2vulnerable
2019-04-07 21:55:33 UTC (acbdaa)3.23.2vulnerable
2019-04-05 11:20:44 UTC (d956f2)3.23.2vulnerable
2019-03-27 00:30:32 UTC (07b42c)3.23.2vulnerable
2019-03-21 05:55:30 UTC (373488)3.23.2vulnerable
2019-03-19 00:35:43 UTC (1222e2)3.23.2vulnerable
2019-03-18 22:50:18 UTC (4c6be1)3.23.2vulnerable
2019-03-16 16:20:42 UTC (da1a2b)3.23.2vulnerable
2019-03-10 06:15:14 UTC (5d3fd3)3.23.2vulnerable
2019-03-05 07:50:31 UTC (34aa25)3.23.2vulnerable
2019-03-02 21:10:38 UTC (26d8a8)3.23.2vulnerable
2019-03-02 17:40:36 UTC (81bf89)3.23.2vulnerable
2019-02-26 19:40:35 UTC (1233c8)3.23.2vulnerable
2019-02-26 18:30:36 UTC (bd0189)3.23.2vulnerable
2019-02-23 21:15:46 UTC (19eeda)3.23.2vulnerable
2019-02-23 13:25:25 UTC (969cff)3.23.2vulnerable
2019-02-22 17:55:42 UTC (2a81ec)3.23.2vulnerable
2019-02-20 15:35:16 UTC (fa82eb)3.23.2vulnerable
2019-02-20 10:40:25 UTC (b75eab)3.23.2vulnerable
2019-02-12 10:30:40 UTC (36f316)3.23.2vulnerable
2019-02-10 08:40:36 UTC (929cc7)3.23.2vulnerable
2019-02-10 03:35:25 UTC (64825d)3.23.2vulnerable
2019-02-10 03:10:30 UTC (baf6ba)3.23.2vulnerable
2019-02-08 21:25:31 UTC (ffc604)3.23.2vulnerable
2019-02-08 08:15:19 UTC (ce8c24)3.23.2vulnerable
2019-02-07 20:30:24 UTC (6a0d2f)3.23.2vulnerable
2019-02-05 03:30:20 UTC (2d6f84)3.23.2vulnerable
2019-02-05 00:05:24 UTC (3bd7a3)3.23.2vulnerable
2019-01-31 04:50:32 UTC (f2a1a4)3.23.2vulnerable
2018-08-31 20:00:16 UTC (083220)3.23.2vulnerable
2018-08-24 12:50:09 UTC (7db611)3.23.2vulnerable
2018-08-17 11:25:34 UTC (8395f9)3.23.2vulnerable
2018-08-13 14:40:22 UTC (6afd19)3.23.2vulnerable
2018-08-13 09:35:37 UTC (a01850)3.23.2vulnerable
2018-08-12 20:15:12 UTC (4af9ee)3.23.2vulnerable
2018-08-12 02:10:25 UTC (b5b11e)3.23.2vulnerable
2018-08-11 19:25:19 UTC (bd4ef2)3.23.2vulnerable
2018-08-02 04:50:18 UTC (2428f5)3.23.2vulnerable
2018-07-31 15:45:38 UTC (7c5852)3.23.2vulnerable
2018-07-11 16:40:22 UTC (dae9cf)3.23.2vulnerable
2018-07-08 19:55:08 UTC (2a8a55)3.23.2vulnerable
2018-07-08 16:40:22 UTC (784f54)3.23.2vulnerable
2018-07-06 19:55:40 UTC (fda46a)3.23.2vulnerable
2018-07-02 04:50:18 UTC (be1461)3.23.2vulnerable
2018-07-01 00:20:18 UTC (687f5d)3.23.2vulnerable
2018-06-30 12:30:34 UTC (85497a)3.23.2vulnerable
2018-06-29 19:45:17 UTC (e686bd)3.23.2vulnerable
2018-06-22 13:15:24 UTC (a8c710)3.23.2vulnerable
2018-06-14 21:57:20 UTC (4b649a)3.23.2vulnerable