CVE-2019-11932

HIGH

android-gif-drawable <1.2.18 - RCE

Title source: llm

Description

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

Exploits (24)

nomisec WORKING POC 268 stars
by dorkerdevil · poc
https://github.com/dorkerdevil/CVE-2019-11932
nomisec WORKING POC 208 stars
by awakened1712 · poc
https://github.com/awakened1712/CVE-2019-11932
nomisec WORKING POC 38 stars
by valbrux · poc
https://github.com/valbrux/CVE-2019-11932-SupportApp
nomisec WORKING POC 33 stars
by Err0r-ICA · poc
https://github.com/Err0r-ICA/WhatsPayloadRCE
nomisec SUSPICIOUS 25 stars
by kal1gh0st · poc
https://github.com/kal1gh0st/WhatsAppHACK-RCE
nomisec WORKING POC 17 stars
by fastmo · poc
https://github.com/fastmo/CVE-2019-11932
nomisec WORKING POC 16 stars
by mRanonyMousTZ · poc
https://github.com/mRanonyMousTZ/CVE-2019-11932-whatsApp-exploit
nomisec WORKING POC 6 stars
by SmoZy92 · poc
https://github.com/SmoZy92/CVE-2019-11932
nomisec WRITEUP 4 stars
by infiniteLoopers · poc
https://github.com/infiniteLoopers/CVE-2019-11932
nomisec WORKING POC 4 stars
by JasonJerry · poc
https://github.com/JasonJerry/WhatsRCE
nomisec WORKING POC 4 stars
by TulungagungCyberLink · poc
https://github.com/TulungagungCyberLink/CVE-2019-11932
nomisec WORKING POC 1 stars
by tucommenceapousser · poc
https://github.com/tucommenceapousser/CVE-2019-11932
nomisec STUB 1 stars
by Tabni · poc
https://github.com/Tabni/https-github.com-awakened1712-CVE-2019-11932
nomisec WORKING POC 1 stars
by tucommenceapousser · poc
https://github.com/tucommenceapousser/CVE-2019-11932deta
nomisec STUB 1 stars
by zxn1 · poc
https://github.com/zxn1/CVE-2019-11932
gitlab WORKING POC
by mdelaclaire · poc
https://gitlab.com/mdelaclaire/CVE-2019-11932deta
gitlab WORKING POC
by gavz · poc
https://gitlab.com/gavz/CVE-2019-11932
nomisec WORKING POC
by primebeast · poc
https://github.com/primebeast/CVE-2019-11932
nomisec WORKING POC
by starling021 · poc
https://github.com/starling021/CVE-2019-11932-SupportApp
nomisec STUB
by 0759104103 · poc
https://github.com/0759104103/cd-CVE-2019-11932
nomisec WRITEUP
by k3vinlusec · poc
https://github.com/k3vinlusec/WhatsApp-Double-Free-Vulnerability_CVE-2019-11932
exploitdb WORKING POC
by Valerio Brussani · c++remoteandroid
https://www.exploit-db.com/exploits/47515

Scores

CVSS v3 8.8
EPSS 0.7171
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-415
Status published

Affected Products (3)

whatsapp/whatsapp < 2.19.244
android-gif-drawable_project/android-gif-drawable < 1.2.18
pl.droidsonroids.gif/android-gif-drawable < 1.2.18Maven

Timeline

Published Oct 03, 2019
Tracked Since Feb 18, 2026