VulnerabilityModified
CVE-2018-6344
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established.
HIGH 7.5EPSS 1.95%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.95%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android prior to v2.18.293, WhatsApp for iOS prior to v2.18.93, and WhatsApp for Windows Phone prior to v2.18.172.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-122, CWE-787
- Affected
- whatsapp/whatsapp
- Source
- cve-assign@fb.com
References
- http://www.securityfocus.com/bid/106365Third Party Advisory, VDB Entry
- https://googleprojectzero.blogspot.com/2018/12/adventures-in-video-conferencing-part-3.htmlExploit, Third Party Advisory
- http://www.securityfocus.com/bid/106365Third Party Advisory, VDB Entry
- https://googleprojectzero.blogspot.com/2018/12/adventures-in-video-conferencing-part-3.htmlExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.