First published: Tue Oct 06 2020(Updated: )
A buffer overflow in WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 could have allowed an out-of-bounds write when processing malformed local videos with E-AC-3 audio streams.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Whatsapp Whatsapp | <2.20.130 | |
Whatsapp Whatsapp Business | <2.20.46 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-1906.
The severity of CVE-2020-1906 is high with a severity value of 7.8.
WhatsApp for Android prior to v2.20.130 and WhatsApp Business for Android prior to v2.20.46 are affected by CVE-2020-1906.
An attacker can exploit CVE-2020-1906 by sending malformed local videos with E-AC-3 audio streams, triggering a buffer overflow and allowing an out-of-bounds write.
To fix CVE-2020-1906, upgrade to WhatsApp for Android v2.20.130 or later, and WhatsApp Business for Android v2.20.46 or later.