9.8

CVE-2020-1907

A stack overflow in WhatsApp for Android prior to v2.20.196.16, WhatsApp Business for Android prior to v2.20.196.12, WhatsApp for iOS prior to v2.20.90, WhatsApp Business for iOS prior to v2.20.90, and WhatsApp for Portal prior to v173.0.0.29.505 could have allowed arbitrary code execution when parsing the contents of an RTP Extension header.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WhatsApp ≫ WhatsApp SwPlatform iphone_os Version < 2.20.90
WhatsApp ≫ WhatsApp SwPlatform android Version < 2.20.196.16
WhatsApp ≫ WhatsApp SwPlatform portal Version < 173.0.0.29.505
WhatsApp ≫ WhatsApp Business SwPlatform iphone_os Version < 2.20.90
WhatsApp ≫ WhatsApp Business SwPlatform android Version < 2.20.196.12
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.89% 0.77
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://www.whatsapp.com/security/advisories/2020/
Vendor Advisory