GHSA-x534-j49x-mqvj

Suggest an improvement
Source
https://github.com/advisories/GHSA-x534-j49x-mqvj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x534-j49x-mqvj/GHSA-x534-j49x-mqvj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-x534-j49x-mqvj
Aliases
Published
2022-05-24T16:57:50Z
Modified
2025-01-13T15:57:04.734138Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
android-gif-drawable Double Free vulnerability
Details

A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.

Database specific
{
    "nvd_published_at": "2019-10-03T22:15:00Z",
    "cwe_ids": [
        "CWE-415"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2025-01-13T15:21:40Z"
}
References

Affected packages

Maven / pl.droidsonroids.gif:android-gif-drawable

Package

Name
pl.droidsonroids.gif:android-gif-drawable
View open source insights on deps.dev
Purl
pkg:maven/pl.droidsonroids.gif/android-gif-drawable

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.18

Affected versions

1.*

1.0.6
1.0.7
1.0.8
1.0.9
1.0.10
1.0.11
1.0.12
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.1.8
1.1.9
1.1.10
1.1.11
1.1.12
1.1.13
1.1.14
1.1.15
1.1.16
1.1.17
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17