5
CVSSv2

CVE-2014-2209

Published: 28/12/2014 Updated: 30/12/2014
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Facebook HipHop Virtual Machine (HHVM) prior to 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote malicious users to bypass intended access restrictions by leveraging group permissions for a file or directory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

facebook hiphop virtual machine