PT-2020-15157 · Facebook · Whatsapp For Ios+1

Published

2020-10-06

·

Updated

2020-10-19

·

CVE-2020-1903

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WhatsApp for iOS versions prior to 2.20.61 WhatsApp Business for iOS versions prior to 2.20.61
Description An issue with unzipping docx, pptx, and xlsx documents could result in an out-of-memory denial of service. The issue would require the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts.
Recommendations For WhatsApp for iOS versions prior to 2.20.61, update to version 2.20.61 or later. For WhatsApp Business for iOS versions prior to 2.20.61, update to version 2.20.61 or later.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-1903

Affected Products

Whatsapp Business For Ios
Whatsapp For Ios