René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

143 lines
4.7 KiB
JSON

{
"id": "CVE-2018-6350",
"sourceIdentifier": "cve-assign@fb.com",
"published": "2019-06-14T17:29:02.283",
"lastModified": "2019-06-18T17:15:10.157",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "An out-of-bounds read was possible in WhatsApp due to incorrect parsing of RTP extension headers. This issue affects WhatsApp for Android prior to 2.18.276, WhatsApp Business for Android prior to 2.18.99, WhatsApp for iOS prior to 2.18.100.6, WhatsApp Business for iOS prior to 2.18.100.2, and WhatsApp for Windows Phone prior to 2.18.224."
},
{
"lang": "es",
"value": "Fue posible una lectura fuera de l\u00edmites en WhatsApp debido a un an\u00e1lisis incorrecto de los encabezados de extensi\u00f3n RTP. Este problema afecta a WhatsApp para Android anterior a versi\u00f3n 2.18.276, WhatsApp Business para Android anterior a versi\u00f3n 2.18.99, WhatsApp para iOS anterior a versi\u00f3n 2.18.100.6, WhatsApp Business para iOS anterior a versi\u00f3n 2.18.100.2 y WhatsApp para Windows Phone anterior a versi\u00f3n 2.18. 224."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL"
},
"exploitabilityScore": 3.9,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 7.5
},
"baseSeverity": "HIGH",
"exploitabilityScore": 10.0,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
},
{
"source": "cve-assign@fb.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:android:*:*",
"versionEndExcluding": "2.18.99",
"matchCriteriaId": "139F635A-0B95-4E79-BE42-1EF2CE5A8F40"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:business:iphone_os:*:*",
"versionEndExcluding": "2.18.100.2",
"matchCriteriaId": "F1B47F84-5362-4C2D-917B-E46580242858"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*",
"versionEndExcluding": "2.18.100.6",
"matchCriteriaId": "441C5C11-D968-4BC4-ADA8-E16B5174B8DB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:windows_phone:*:*",
"versionEndExcluding": "2.18.224",
"matchCriteriaId": "CF68727A-1D7F-4A59-A35B-B4D1B3F5929F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:business:android:*:*",
"versionEndExcluding": "2.18.276",
"matchCriteriaId": "F9A5B45E-FA04-498E-A169-C016937F8E2F"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/108803",
"source": "cve-assign@fb.com"
},
{
"url": "https://www.facebook.com/security/advisories/cve-2018-6350/",
"source": "cve-assign@fb.com",
"tags": [
"Third Party Advisory"
]
}
]
}