Double Free in android-gif-drawable - CVE-2019-11932
Published: October 6, 2019 / Updated: September 27, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the DDGifSlurp() function in decoding.c. A remote attacker can create a specially crafted GIF file, pass it to the affected application, trigger a double free error and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
WhatsApp Messenger for Android
How to mitigate CVE-2019-11932
WhatsApp Messenger for Android - update to 2.19.244
Links to Public Exploits and PoC-codes
- Exploit #9360 - CVE-2019-11932 (Double-Free BUG in WhatsApp exploit poc.) (September 27, 2023)
- Exploit #9359 - CVE-2019-11932deta (Double-Free BUG in WhatsApp exploit poc.) (September 27, 2023)
- Exploit #8081 - WhatsPayloadRCE (Whatsapp Automatic Payload Generator [CVE-2019-11932]) (June 26, 2022)
- Exploit #5871 - Whatsapp 2.19.216 - Remote Code Execution (June 17, 2021)
- Exploit #5556 - CVE-2019-11932 (The exploit works well until WhatsApp version 2.19.230. The vulnerability is official patched in WhatsApp version 2.19.244) (June 13, 2021)
- Exploit #2028 - CVE-2019-11932 (Double-Free BUG in WhatsApp exploit poc.) (March 18, 2020)
- Exploit #2029 - CVE-2019-11932 (The exploit works well until WhatsApp version 2.19.230. The vulnerability is official patched in WhatsApp version 2.19.244) (March 18, 2020)
- Exploit #2040 - CVE-2019-11932-SupportApp (This native code file aims to be complementary to the published Whatsapp GIF RCE exploit by Awakened , by calculating the system() function address and ROP gadget address for different types of devices, which then can be used to (March 18, 2020)
- Exploit #2041 - CVE-2019-11932 (Programa para hackear Whatsapp Mediante Gif ,asiendo un exploit con el puerto.) (March 18, 2020)
- Exploit #2044 - CVE-2019-11932-whatsApp-exploit (Double-free vulnerability in DDGifSlurp in decoding.c in libpl_droidsonroids_gif can read more https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/) (March 18, 2020)
- Exploit #2064 - CVE-2019-11932 (Simple POC for exploiting WhatsApp double-free bug in DDGifSlurp in decoding.c in libpl_droidsonroids_gif) (March 18, 2020)
- Exploit #269 - CVE-2019-11932 ( double-free bug in WhatsApp exploit poc) (March 18, 2020)