668
VMScore

CVE-2019-11933

Published: 23/10/2019 Updated: 14/09/2021
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A heap buffer overflow bug in libpl_droidsonroids_gif prior to 1.2.19, as used in WhatsApp for Android before version 2.19.291 could allow remote malicious users to execute arbitrary code or cause a denial of service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libpl droidsonroids gif project libpl droidsonroids gif

whatsapp whatsapp

Github Repositories

Heap corruption in WhatsApp's media picker

CVE-2019-11933 Heap corruption in WhatsApp's media picker affecting WhatsApp for android before version 219291 Background A GIF file is divided into segments, marked by a specific byte: Image (0x2C) The image section describes a single frame in the GIF file, and contains information such as the height, width, as well as the compressed image itself A GIF can have multi