{"id":"GHSA-x534-j49x-mqvj","summary":"android-gif-drawable Double Free vulnerability","details":"A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.","aliases":["CVE-2019-11932"],"modified":"2025-01-13T15:57:04.734138Z","published":"2022-05-24T16:57:50Z","database_specific":{"github_reviewed_at":"2025-01-13T15:21:40Z","nvd_published_at":"2019-10-03T22:15:00Z","cwe_ids":["CWE-415"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11932"},{"type":"WEB","url":"https://github.com/koral--/android-gif-drawable/pull/673"},{"type":"WEB","url":"https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9"},{"type":"WEB","url":"https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20"},{"type":"WEB","url":"https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce"},{"type":"WEB","url":"https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263"},{"type":"PACKAGE","url":"https://github.com/koral--/android-gif-drawable"},{"type":"WEB","url":"https://www.facebook.com/security/advisories/cve-2019-11932"},{"type":"WEB","url":"http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html"},{"type":"WEB","url":"http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html"},{"type":"WEB","url":"http://seclists.org/fulldisclosure/2019/Nov/27"}],"affected":[{"package":{"name":"pl.droidsonroids.gif:android-gif-drawable","ecosystem":"Maven","purl":"pkg:maven/pl.droidsonroids.gif/android-gif-drawable"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.18"}]}],"versions":["1.0.10","1.0.11","1.0.12","1.0.6","1.0.7","1.0.8","1.0.9","1.1.0","1.1.1","1.1.10","1.1.11","1.1.12","1.1.13","1.1.14","1.1.15","1.1.16","1.1.17","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8","1.1.9","1.2.0","1.2.1","1.2.10","1.2.11","1.2.12","1.2.13","1.2.14","1.2.15","1.2.16","1.2.17","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x534-j49x-mqvj/GHSA-x534-j49x-mqvj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}