Описание
A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.21.3 (исключая)Версия до 2.21.3 (исключая)Версия до 2.21.3 (исключая)Версия до 2.21.32 (исключая)
Одно из
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*
cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:android:*:*
cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 63%
0.00442
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-787
CWE-787
Связанные уязвимости
github
больше 3 лет назад
A missing bounds check within the audio decoding pipeline for WhatsApp calls in WhatsApp for Android prior to v2.21.3, WhatsApp Business for Android prior to v2.21.3, WhatsApp for iOS prior to v2.21.32, and WhatsApp Business for iOS prior to v2.21.32 could have allowed an out-of-bounds write.
EPSS
Процентиль: 63%
0.00442
Низкий
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
CWE-787
CWE-787