CVE-2019-11932
40Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendepss 44%
da publicação à arma0 dias
Publicada no NVD3 de out.
1ª PoC3 de out.
probabilidade de exploração
44%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
21 exploit(s) público(s)
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Produtos afetados
koral-- · android-gif-drawablePoCs públicas encontradas — 21
exploitdbwww.exploit-db.com/exploits/47515não verificadogithubgithub.com/dorkerdevil/CVE-2019-11932★ 267githubgithub.com/awakened1712/CVE-2019-11932★ 208githubgithub.com/valbrux/CVE-2019-11932-SupportApp★ 38githubgithub.com/Err0r-ICA/WhatsPayloadRCE★ 36githubgithub.com/kal1gh0st/WhatsAppHACK-RCE★ 27githubgithub.com/fastmo/CVE-2019-11932★ 17githubgithub.com/mRanonyMousTZ/CVE-2019-11932-whatsApp-exploit★ 16githubgithub.com/SmoZy92/CVE-2019-11932★ 6githubgithub.com/TulungagungCyberLink/CVE-2019-11932★ 4githubgithub.com/infiniteLoopers/CVE-2019-11932★ 4githubgithub.com/JasonJerry/WhatsRCE★ 4githubgithub.com/Tabni/https-github.com-awakened1712-CVE-2019-11932★ 1githubgithub.com/k3vinlusec/WhatsApp-Double-Free-Vulnerability_CVE-2019-11932★ 0githubgithub.com/BadAssAiras/hello★ 0githubgithub.com/0759104103/cd-CVE-2019-11932★ 0githubgithub.com/OrdaraatSite/https-github.com-awakened171★ 0githubgithub.com/starling021/CVE-2019-11932-SupportApp★ 0githubgithub.com/primebeast/CVE-2019-11932★ 0cve_referencepacketstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlnão verificadocve_referencepacketstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.
Referências
http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlhttps://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/http://seclists.org/fulldisclosure/2019/Nov/27https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20https://github.com/koral--/android-gif-drawable/pull/673https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9https://www.facebook.com/security/advisories/cve-2019-11932