CVE-2018-16132

HIGH

Signal < 2.29.0 - Denial of Service via Large Image Rendering

Title source: llm
STIX 2.1

Description

The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device.

References (1)

Core 1
Core References
Mailing List, Third Party Advisory x_refsource_misc
http://seclists.org/bugtraq/2018/Aug/57

Scores

CVSS v3 8.6
EPSS 0.0109
EPSS Percentile 61.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (1)
signal/signal < 2.29.0
Published Aug 29, 2018
Tracked Since Feb 18, 2026