CVE-2019-11932
Whatsapp 2.19.216 - Remote Code Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
17Exploited in Wild
-Decision
Descriptions
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Una vulnerabilidad doble gratuita en la función DDGifSlurp en decoding.c en la biblioteca android-gif-drawable antes de la versión 1.2.18, como se usa en WhatsApp para Android antes de la versión 2.19.244 y muchas otras aplicaciones de Android, permite a los atacantes remotos ejecutar código arbitrario o causar una denegación de servicio cuando la biblioteca se utiliza para analizar una imagen GIF especialmente diseñada.
Whatsapp version 2.19.216 suffers from a remote code execution vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-13 CVE Reserved
- 2019-10-03 CVE Published
- 2019-10-06 First Exploit
- 2024-08-04 CVE Updated
- 2024-09-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-415: Double Free
CAPEC
References (25)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html | Third Party Advisory | |
http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html | Third Party Advisory | |
http://seclists.org/fulldisclosure/2019/Nov/27 | Mailing List | |
https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263 | Third Party Advisory | |
https://github.com/koral--/android-gif-drawable/pull/673 | Third Party Advisory | |
https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9 | Third Party Advisory | |
https://www.facebook.com/security/advisories/cve-2019-11932 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20 | 2023-03-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Whatsapp Search vendor "Whatsapp" | Whatsapp Search vendor "Whatsapp" for product "Whatsapp" | < 2.19.244 Search vendor "Whatsapp" for product "Whatsapp" and version " < 2.19.244" | android |
Affected
| ||||||
Android-gif-drawable Project Search vendor "Android-gif-drawable Project" | Android-gif-drawable Search vendor "Android-gif-drawable Project" for product "Android-gif-drawable" | < 1.2.18 Search vendor "Android-gif-drawable Project" for product "Android-gif-drawable" and version " < 1.2.18" | - |
Affected
|