CVE-2019-11932
40Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 44%
from disclosure to weapon0 days
Published on NVDOct 3
1st PoCOct 3
exploitation probability
44%top 1% of all CVEs
observed exploitation
nono source reports it
21 public exploit(s)
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Affected products
koral-- · android-gif-drawablepublic PoCs found — 21
exploitdbwww.exploit-db.com/exploits/47515unverifiedgithubgithub.com/dorkerdevil/CVE-2019-11932★ 267githubgithub.com/awakened1712/CVE-2019-11932★ 208githubgithub.com/valbrux/CVE-2019-11932-SupportApp★ 38githubgithub.com/Err0r-ICA/WhatsPayloadRCE★ 36githubgithub.com/kal1gh0st/WhatsAppHACK-RCE★ 27githubgithub.com/fastmo/CVE-2019-11932★ 17githubgithub.com/mRanonyMousTZ/CVE-2019-11932-whatsApp-exploit★ 16githubgithub.com/SmoZy92/CVE-2019-11932★ 6githubgithub.com/TulungagungCyberLink/CVE-2019-11932★ 4githubgithub.com/infiniteLoopers/CVE-2019-11932★ 4githubgithub.com/JasonJerry/WhatsRCE★ 4githubgithub.com/Tabni/https-github.com-awakened1712-CVE-2019-11932★ 1githubgithub.com/k3vinlusec/WhatsApp-Double-Free-Vulnerability_CVE-2019-11932★ 0githubgithub.com/BadAssAiras/hello★ 0githubgithub.com/0759104103/cd-CVE-2019-11932★ 0githubgithub.com/OrdaraatSite/https-github.com-awakened171★ 0githubgithub.com/starling021/CVE-2019-11932-SupportApp★ 0githubgithub.com/primebeast/CVE-2019-11932★ 0cve_referencepacketstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.htmlhttps://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/http://seclists.org/fulldisclosure/2019/Nov/27https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20https://github.com/koral--/android-gif-drawable/pull/673https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9https://www.facebook.com/security/advisories/cve-2019-11932