Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6350

Опубликовано: 14 июн. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*
Версия до 2.18.99 (исключая)
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
Версия до 2.18.100.6 (исключая)
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows_phone:*:*
Версия до 2.18.224 (исключая)
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*
Версия до 2.18.100.2 (исключая)
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*
Версия до 2.18.276 (исключая)

EPSS

Процентиль: 60%
0.00398
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-125
CWE-125

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224.

EPSS

Процентиль: 60%
0.00398
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-125
CWE-125