VDB
CVE-2019-11932
CVE-2019-11932
PUBLISHED
CVSS 8.800000190734863 HIGH
android-gif-drawable Double Free vulnerability
EPSS 44.53% · 98.7th percentile
Risk Scores
CVSS 3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
44.53%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| koral-- | android-gif-drawable | unspecified |
| android-gif-drawable_project | android-gif-drawable | 0 |
| 0 | ||
| Maven | pl.droidsonroids.gif:android-gif-drawable | 0 |
Timeline
- Oct 3, 2019 CVE Published
- Oct 17, 2019 PoC Published
- Nov 29, 2019 PoC Published
- Oct 9, 2020 PoC Published
- Oct 9, 2020 PoC Published
- Apr 14, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/ url
- https://www.facebook.com/security/advisories/cve-2019-11932 url
- https://github.com/koral--/android-gif-drawable/pull/673 url
- http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html advisory
- http://seclists.org/fulldisclosure/2019/Nov/27 mailing_list
- https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263 advisory
- https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20 patch
- https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11932 advisory
- https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce url
- https://github.com/koral--/android-gif-drawable package
- http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html url