First published: Wed Aug 29 2018(Updated: )
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Signal Signal | <=2.29.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-16132.
The severity of CVE-2018-16132 is high with a score of 8.6.
The Open Whisper Signal app versions up to and including 2.29.0 for iOS are affected by CVE-2018-16132.
CVE-2018-16132 allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a denial of service condition.
Yes, upgrading to a version higher than 2.29.0 of the Open Whisper Signal app for iOS will fix CVE-2018-16132.