{"id":"CVE-2019-11932","details":"A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.","aliases":["GHSA-x534-j49x-mqvj"],"modified":"2026-07-08T15:55:08.171721Z","published":"2019-10-03T22:15:10.370Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*"],"extracted_events":[{"fixed":"2.19.244"}],"source":"CPE_RANGE","vendor_product":"whatsapp:whatsapp"}]},"references":[{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Nov/27"},{"type":"ADVISORY","url":"https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263"},{"type":"ADVISORY","url":"https://github.com/koral--/android-gif-drawable/pull/673"},{"type":"ADVISORY","url":"https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2019-11932"},{"type":"FIX","url":"https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20"},{"type":"EVIDENCE","url":"https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/koral--/android-gif-drawable","events":[{"introduced":"0"},{"fixed":"78df8feb91d8d2557b808494bef24eec91a274d3"},{"fixed":"cc5b4f8e43463995a84efd594f89a21f906c2d20"}],"database_specific":{"cpe":"cpe:2.3:a:android-gif-drawable_project:android-gif-drawable:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.2.18"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v1.2.16","v1.2.10","v1.2.6","v1.2.5","v1.2.4","v1.2.2","v1.2.1","v1.2.0","v1.1.17","v1.1.16","v1.1.15","v1.1.14","v1.1.13","v1.1.12","v1.1.11","v1.1.10","v1.1.9","v1.1.8","v1.1.7","v1.1.6","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.12","v1.0.11","v1.0.10","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11932.json","vanir_signatures_modified":"2026-07-08T15:55:08Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["307494684151968822352496849915942941334","179646405047686153803200246891620737399","3565184496671623564557538637471165139","319716975894053961623641977136312660817","247672870486026284567417504325281799838","231133232878314181211603384170963396143"],"threshold":0.9},"id":"CVE-2019-11932-20c00734","signature_type":"Line","signature_version":"v1","source":"https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20","target":{"file":"android-gif-drawable/src/main/c/decoding.c"}},{"target":{"file":"android-gif-drawable/src/main/c/decoding.c","function":"DDGifSlurp"},"deprecated":false,"digest":{"function_hash":"256783787093088157937719302303409991667","length":3101},"id":"CVE-2019-11932-e657e0c4","signature_type":"Function","signature_version":"v1","source":"https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}