Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-1909

Опубликовано: 03 нояб. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
Версия до 2.20.111 (исключая)
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*
Версия до 2.20.111 (исключая)

EPSS

Процентиль: 76%
0.00938
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-416
CWE-416

Связанные уязвимости

github
больше 3 лет назад

A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.20.111 could have resulted in memory corruption, crashes and potentially code execution. This could have happened only if several events occurred together in sequence, including receiving an animated sticker while placing a WhatsApp video call on hold.

EPSS

Процентиль: 76%
0.00938
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-416
CWE-416