Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17192

Опубликовано: 05 окт. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:signal:private_messenger:*:*:*:*:*:android:*:*
Версия до 4.47.7 (включая)

EPSS

Процентиль: 78%
0.01154
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-670

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

** DISPUTED ** The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs.

EPSS

Процентиль: 78%
0.01154
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-670