CVE-2019-11932
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 44.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 44.53% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- whatsapp/whatsapp · android-gif-drawable project/android-gif-drawable
- Source
- cve-assign@fb.com
References
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/27Mailing List, Third Party Advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/Exploit, Third Party Advisory
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263Third Party Advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20Patch, Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2019-11932Third Party Advisory
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Nov/27Mailing List, Third Party Advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/Exploit, Third Party Advisory
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263Third Party Advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20Patch, Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673Third Party Advisory
- https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9Third Party Advisory
- https://www.facebook.com/security/advisories/cve-2019-11932Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.