Insufficient type checks were employed prior to casting input data in SimpleXMLElementexportNode and simplexmlimport_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.0 and 3.14.1 (inclusive).
[
{
"signature_version": "v1",
"source": "https://github.com/facebook/hhvm/commit/8e7266fef1f329b805b37f32c9ad0090215ab269",
"deprecated": false,
"target": {
"file": "hphp/runtime/ext/simplexml/ext_simplexml.cpp",
"function": "SimpleXMLElement_exportNode"
},
"id": "CVE-2016-1000004-7e68cc5a",
"digest": {
"function_hash": "284111172822097489879350956689906283064",
"length": 208.0
},
"signature_type": "Function"
},
{
"signature_version": "v1",
"source": "https://github.com/facebook/hhvm/commit/8e7266fef1f329b805b37f32c9ad0090215ab269",
"deprecated": false,
"target": {
"file": "hphp/runtime/ext/simplexml/ext_simplexml.cpp"
},
"id": "CVE-2016-1000004-d2f0dcbc",
"digest": {
"threshold": 0.9,
"line_hashes": [
"55765914228621558646643659540904023927",
"243835335827319018911730436790814189705",
"79200780020579073968261204415201624069",
"278751480322904910959016944884515555258",
"198200089604599280099251079262852164476",
"68225021353284281926992865200273145178",
"40146257546414192642961160745671104275",
"87266853421619007164937883201537336780",
"211421453706724789124054905841163514856",
"152257111440568270577492985775885413759"
]
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/facebook/hhvm/commit/8e7266fef1f329b805b37f32c9ad0090215ab269",
"deprecated": false,
"target": {
"file": "hphp/runtime/ext/simplexml/ext_simplexml.cpp",
"function": "HHVM_FUNCTION"
},
"id": "CVE-2016-1000004-e0136018",
"digest": {
"function_hash": "96267759177677574329934507567798237337",
"length": 831.0
},
"signature_type": "Function"
}
]