CVE-2019-11932: Double Free
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-11932?
CVE-2019-11932 is a double free vulnerability in the DDGifSlurp function in the android-gif-drawable library before version 1.2.18, allowing remote attackers to execute arbitrary code or cause a denial of service.
Which software is affected by CVE-2019-11932?
WhatsApp for Android versions up to 2.19.244 and other Android applications using the android-gif-drawable library versions up to 1.2.18 are affected by CVE-2019-11932.
How severe is CVE-2019-11932?
CVE-2019-11932 has a severity score of 8.8 (high).
How can CVE-2019-11932 be exploited?
CVE-2019-11932 can be exploited by remote attackers to execute arbitrary code or cause a denial of service.
Is there a fix available for CVE-2019-11932?
Yes, updating to android-gif-drawable library version 1.2.18 or above and WhatsApp for Android version 2.19.244 or above will fix CVE-2019-11932.