HIGH

CVE-2019-11932

CVSS v3

8.8

HIGH

EPSS Score

82.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

Technical details

Published
10/3/2019

Frequently asked questions

What is CVE-2019-11932?

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

Is CVE-2019-11932 actively exploited?

Active exploitation of CVE-2019-11932 has not been confirmed. The EPSS score is 82.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-11932?

CVE-2019-11932 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2019-11932 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.