CVE-2019-11932
Last modified
CVE-2019-11932 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.. EPSS estimates a 44.53% chance of exploitation in the next 30 days.
Description
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| < 2.19.244 | ||
| Android-Gif-Drawable Project | Android-Gif-Drawable | < 1.2.18 |
References
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/27Mailing List, Third Party Advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/Exploit, Third Party Advisory
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263Third Party Advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20Patch, Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2019-11932Third Party Advisory
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/27Mailing List, Third Party Advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/Exploit, Third Party Advisory
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263Third Party Advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20Patch, Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2019-11932Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-11932?
How severe is CVE-2019-11932?
How do I fix CVE-2019-11932?
Are you affected by CVE-2019-11932?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
