PT-2019-12567 · Facebook · Whatsapp Business For Ios+3

Publicado

2019-11-14

·

Atualizado

2019-11-19

·

CVE-2019-11931

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WhatsApp versions prior to 2.19.274 (Android) WhatsApp versions prior to 2.19.100 (iOS) WhatsApp Enterprise Client versions prior to 2.25.3 WhatsApp Business for Android versions prior to 2.19.104 WhatsApp Business for iOS versions prior to 2.19.100
Description A stack-based buffer overflow could be triggered by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a Denial of Service (DoS) or Remote Code Execution (RCE). This could allow attackers to hack targeted devices remotely and install spyware on them.
Recommendations For Android versions prior to 2.19.274, update to version 2.19.274 or later. For iOS versions prior to 2.19.100, update to version 2.19.100 or later. For Enterprise Client versions prior to 2.25.3, update to version 2.25.3 or later. For Business for Android versions prior to 2.19.104, update to version 2.19.104 or later. For Business for iOS versions prior to 2.19.100, update to version 2.19.100 or later. As a temporary workaround, consider avoiding the use of MP4 files in WhatsApp until the issue is resolved.

Exploit

Correção

Stack Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11931

Produtos afetados

Whatsapp
Whatsapp Business For Android
Whatsapp Business For Ios
Whatsapp Enterprise Client