{
	"CVE_data_meta": {
		"ASSIGNER": "cve-assign@fb.com",
		"DATE_ASSIGNED": "2021-01-27",
		"ID": "CVE-2021-24025",
		"STATE": "PUBLIC"
	},
	"affects": {
		"vendor": {
			"vendor_data": [
				{
					"vendor_name": "Facebook",
					"product": {
						"product_data": [
							{
								"product_name": "HHVM",
								"version": {
									"version_data": [
										{
											"version_affected": "!>=",
											"version_value": "4.98.1"
										},
										{
											"version_affected": "=",
											"version_value": "4.98.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.97.1"
										},
										{
											"version_affected": "=",
											"version_value": "4.97.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.96.1"
										},
										{
											"version_affected": "=",
											"version_value": "4.96.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.95.1"
										},
										{
											"version_affected": "=",
											"version_value": "4.95.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.94.1"
										},
										{
											"version_affected": "=",
											"version_value": "4.94.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.93.2"
										},
										{
											"version_affected": ">=",
											"version_value": "4.81.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.80.2"
										},
										{
											"version_affected": ">=",
											"version_value": "4.57.0"
										},
										{
											"version_affected": "!>=",
											"version_value": "4.56.3"
										},
										{
											"version_affected": "<",
											"version_value": "4.56.3"
										}
									]
								}
							}
						]
					}
				}
			]
		}
	},
	"data_format": "MITRE",
	"data_type": "CVE",
	"data_version": "4.0",
	"description": {
		"description_data": [
			{
				"lang": "eng",
				"value": "Due to incorrect string size calculations inside the preg_quote function, a large input string passed to the function can trigger an integer overflow leading to a heap overflow. This issue affects HHVM versions prior to 4.56.3, all versions between 4.57.0 and 4.80.1, all versions between 4.81.0 and 4.93.1, and versions 4.94.0, 4.95.0, 4.96.0, 4.97.0, 4.98.0."
			}
		]
	},
	"problemtype": {
		"problemtype_data": [
			{
				"description": [
					{
						"lang": "eng",
						"value": "Heap-based Buffer Overflow (CWE-122)"
					}
				]
			}
		]
	},
	"references": {
		"reference_data": [
			{
				"refsource": "MISC",
				"name": "https://hhvm.com/blog/2021/02/25/security-update.html",
				"url": "https://hhvm.com/blog/2021/02/25/security-update.html"
			},
			{
				"refsource": "MISC",
				"name": "https://github.com/facebook/hhvm/commit/08193b7f0cd3910256e00d599f0f3eb2519c44ca",
				"url": "https://github.com/facebook/hhvm/commit/08193b7f0cd3910256e00d599f0f3eb2519c44ca"
			}
		]
	}
}
