CVE-2019-11932
Last modified
CVE-2019-11932 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.. EPSS estimates a 44.53% chance of exploitation in the next 30 days.
Description
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| < 2.19.244 | ||
| Android-Gif-Drawable Project | Android-Gif-Drawable | < 1.2.18 |
References
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/27Mailing List, Third Party Advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/Exploit, Third Party Advisory
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263Third Party Advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20Patch, Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2019-11932Third Party Advisory
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/27Mailing List, Third Party Advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/Exploit, Third Party Advisory
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263Third Party Advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20Patch, Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2019-11932Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11932?
How severe is CVE-2019-11932?
How do I fix CVE-2019-11932?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-11927An integer overflow in WhatsApp media parsing libraries allo…7.8
- CVE-2019-11928An input validation issue in WhatsApp Desktop versions prior…6.1
- CVE-2019-11929Insufficient boundary checks when formatting numbers in numb…9.8
- CVE-2019-1193A remote code execution vulnerability exists in the way that…6.4
- CVE-2019-11930An invalid free in mb_detect_order can cause the application…9.8
- CVE-2019-11931A stack-based buffer overflow could be triggered in WhatsApp…7.8
- CVE-2019-11933A heap buffer overflow bug in libpl_droidsonroids_gif before…9.8
- CVE-2019-11934Improper handling of close_notify alerts can result in an ou…9.8
- CVE-2019-11935Insufficient boundary checks when processing a string in mb_…9.8
- CVE-2019-11936Various APC functions accept keys containing null bytes as i…9.8
- CVE-2019-11937In Mcrouter prior to v0.41.0, a large struct input provided …7.5
- CVE-2019-11938Java Facebook Thrift servers would not error upon receiving …7.5
Are you affected by CVE-2019-11932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
