CVE-2020-1886: Buffer Overflow
Published Sep 3, 2020
·Updated
A buffer overflow in WhatsApp for Android prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 could have allowed an out-of-bounds write via a specially crafted video stream after receiving and answering a malicious video call.
Affected Software
2 affected components
WhatsApp Whatsapp Android<2.20.11
WhatsApp Whatsapp Business Android<2.20.2
Event History
Sep 3, 2020
CVE Published
via MITRE·09:10 PM
Data Sourced
via MITRE·09:10 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-1886.
2
What is the severity of CVE-2020-1886?
The severity of CVE-2020-1886 is high.
3
Which software versions are affected by CVE-2020-1886?
WhatsApp for Android versions prior to v2.20.11 and WhatsApp Business for Android prior to v2.20.2 are affected by CVE-2020-1886.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by a specially crafted video stream after receiving and answering a malicious video call.
5
Is there a fix available for CVE-2020-1886?
Yes, updating WhatsApp for Android to v2.20.11 and WhatsApp Business for Android to v2.20.2 or later versions fixes CVE-2020-1886.