Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-39595 | HHVM 4.172.0 and all prior versions use TLS 1.0 for secure connections when handling tls:// URLs in the stream extension. TLS1.0 has numerous published vulnerabilities and is deprecated. HHVM 4.153.4, 4.168.2, 4.169.2, 4.170.2, 4.171.1, 4.172.1, 4.173.0 replaces TLS1.0 with TLS1.3. Applications that call stream_socket_server or stream_socket_client functions with a URL starting with tls:// are affected. |
Mon, 27 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-327 | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-01-27T18:25:06.548Z
Reserved: 2022-07-27T17:00:55.528Z
Link: CVE-2022-36937
Updated: 2024-08-03T10:21:32.009Z
Status : Modified
Published: 2023-05-10T19:15:08.627
Modified: 2025-01-27T19:15:13.297
Link: CVE-2022-36937
No data.
OpenCVE Enrichment
No data.
EUVD