CVE-2020-27853: Critical severity wire vulnerability
Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string. This affects Wire AVS (Audio, Video, and Signaling) 5.3 through 6.x before 6.4, the Wire Secure Messenger application before 3.49.918 for Android, and the Wire Secure Messenger application before 3.61 for iOS. This occurs via the value parameter to sdpmediasetlattr in peerflow/sdp.c.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-27853?
CVE-2020-27853 is a vulnerability that allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string.
Which software versions are affected by CVE-2020-27853?
Wire AVS (Audio, Video, and Signaling) versions 5.3 through 6.x before 6.4, Wire Secure Messenger application before 3.49.918 for Android, and Wire Secure Messenger application before 3.61 for iPhone OS are affected.
What is the severity of CVE-2020-27853?
CVE-2020-27853 has a severity rating of 9.8 (critical).
How can CVE-2020-27853 be exploited?
CVE-2020-27853 can be exploited by remote attackers through a format string vulnerability.
Are there any references for CVE-2020-27853?
Yes, you can find references for CVE-2020-27853 at the following links: - [http://github.security.telekom.com/2020/11/wire-secure-messenger-format-string-vulnerability.html](http://github.security.telekom.com/2020/11/wire-secure-messenger-format-string-vulnerability.html) - [https://github.com/wireapp/wire-audio-video-signaling/issues/23#issuecomment-710075689](https://github.com/wireapp/wire-audio-video-signaling/issues/23#issuecomment-710075689)