CVE-2019-17192: Critical severity signal private messenger vulnerability
DISPUTED The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17192?
CVE-2019-17192 is a vulnerability in the WebRTC component of the Signal Private Messenger application for Android, which could allow remote attackers to cause a denial of service or have other unspecified impact.
How severe is CVE-2019-17192?
CVE-2019-17192 has a severity rating of critical with a CVSS score of 9.8.
How does CVE-2019-17192 affect Signal Private Messenger?
CVE-2019-17192 affects Signal Private Messenger versions up to and including 4.47.7 for Android.
What is the CWE of CVE-2019-17192?
CVE-2019-17192 is classified under CWE-670: Improper Failure to Constrain Operations within the Bounds of a Memory Buffer.
Is there a fix available for CVE-2019-17192?
At the time of this writing, there is no official fix available for CVE-2019-17192. Users are advised to update to the latest version of Signal Private Messenger once a fix is released.