CVE-2020-1903: Medium severity whatsapp vulnerability
Published Oct 6, 2020
·Updated
An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts.
Affected Software
2 affected components
WhatsApp Whatsapp Iphone Os<2.20.61
WhatsApp Whatsapp Business Iphone Os<2.20.61
Event History
Oct 6, 2020
CVE Published
via MITRE·05:35 PM
Data Sourced
via MITRE·05:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-1903.
2
What is the severity of CVE-2020-1903?
The severity of CVE-2020-1903 is medium.
3
Which software versions are affected by this vulnerability?
WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 are affected.
4
What is the impact of this vulnerability?
This vulnerability could result in an out-of-memory denial of service.
5
How can I fix CVE-2020-1903?
To fix CVE-2020-1903, update WhatsApp for iOS and WhatsApp Business for iOS to version 2.20.61 or later.