CVE-2018-6339
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When receiving calls using WhatsApp on Android, a stack allocation failed to properly account for the amount of data being passed in. An off-by-one error meant that data was written beyond the allocated space on the stack. This issue affects WhatsApp for Android starting in version 2.18.180 and was fixed in version 2.18.295. It also affects WhatsApp Business for Android starting in version v2.18.103 and was fixed in version v2.18.150.
Cuando se reciben llamadas con WhatsApp en Android, en la asignación de pila no se considera adecuadamente la cantidad de datos que están pasando. Un error de uno en uno significaba que los datos se escribían fuera del espacio asignado en la pila. Este problema afecta a WhatsApp para Android a partir de la versión 2.18.180 y se corrigió en la versión 2.18.295. También afecta a WhatsApp Business para Android a partir de la versión v2.18.103 y se corrigió en la versión v2.18.150.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-26 CVE Reserved
- 2019-06-14 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.facebook.com/security/advisories/cve-2018-6339 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Whatsapp Search vendor "Whatsapp" | Whatsapp Search vendor "Whatsapp" for product "Whatsapp" | >= 2.18.103 < 2.18.150 Search vendor "Whatsapp" for product "Whatsapp" and version " >= 2.18.103 < 2.18.150" | business, android |
Affected
| ||||||
Whatsapp Search vendor "Whatsapp" | Whatsapp Search vendor "Whatsapp" for product "Whatsapp" | >= 2.18.180 < 2.18.295 Search vendor "Whatsapp" for product "Whatsapp" and version " >= 2.18.180 < 2.18.295" | android |
Affected
|