A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user
Published Nov 14, 2019
7.8
HIGHCVSS 3.1
EPSS 1.21%
Description
A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prior to 2.19.100, Enterprise Client versions prior to 2.25.3, Business for Android versions prior to 2.19.104 and Business for iOS versions prior to 2.19.100.
Affected products
-
Affected
- 2.19.104
- ≥ unspecified, < 2.19.104
-
Affected
- 2.19.100
- ≥ unspecified, < 2.19.100
-
Affected
- 2.25.3
- ≥ unspecified, < 2.25.3
-
Affected
- 2.19.274
- ≥ unspecified, < 2.19.274
-
Affected
- ≥ unspecified, ≤ 2.18.368
-
Affected
- 2.19.100
- ≥ unspecified, < 2.19.100
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| WhatsApp Business for Android | unknown | Affected
| |
| WhatsApp Business for iOS | unknown | Affected
| |
| WhatsApp Enterprise Client | unknown | Affected
| |
| WhatsApp for Android | unknown | Affected
| |
| WhatsApp for Windows Phone | unknown | Affected
| |
| WhatsApp for iOS | unknown | Affected
|
- ≤ 2.18.368
- < 2.19.100
- < 2.19.274
- < 2.19.100
- < 2.19.104
- < 2.25.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3589 Advisory
- https://www.facebook.com/security/advisories/cve-2019-11931 x_refsource_CONFIRMThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-3589 | Advisory | |
| https://www.facebook.com/security/advisories/cve-2019-11931 | x_refsource_CONFIRMThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data