• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

6172

GIF processing vulnerability that is present in WhatsApp patched a vulnerability that allows remote attackers to execute arbitrary code or cause Disk Operating System (DoS) situation. A recently disclosed GIF processing vulnerability has been found impacting thousands of Android applications. The flaw was first discovered in WhatsApp and was eventually patched by its owner Facebook.

OUTLINE

• CVE-2019-11932, which is a vulnerability WhatsApp for Android was first disclosed to the public on October 2, 2019. • The flaw affected a wide range of operating systems. In addition to this, the Android versions which are prior to 2.19.274, iOS versions prior to 2.19.100, Enterprise Client versions prior to 2.25.3, Windows Phone versions before and including 2.18.368, Business for Android versions prior to 2.19.104, and Business for iOS versions prior to 2.19.100. Mostly, older versions are at risk. • The flaw which describes a stack-buffer overflow could be exploited using MP4 video files. It could be potentially allowing an attacker to remotely access messages and files stored in the app. Upon discovery, the flaw was patched by Facebook with the release of WhatsApp version 2.19.244.

IMPACT OF THE VULNERABILITY

Earlier it was mentioned that only WhatsApp was affected, but there are more than 23,000 Android applications that use android -gif-drawable are under risk. These apps are in Google play and with other third-party stores. According to Trend Micro Report, “On Google play alone, we found more than 3000 applications in this vulnerability”. In addition, the Researcher added, “The exploit works well for Android 8.1 and 9.0 but does not work for Android below 8.0”

WHY NOT WHATSAPP?

According to the researcher, who goes by the name Awakened, the vulnerability could have allowed hackers to compromise Android devices remotely, allowing them to steal files and chat messages. CVE-2019-11932, which is a vulnerability WhatsApp for Android is a double-free memory corruption bug that exists in the open-source GIF image library that WhatsApp uses to generate previews for videos, images and GIFs. The researcher stated that the malware triggers when the user opens the image in WhatsApp.

HOW DOES THE FLAW AFFECT THE APPS?

The security flaw previously causing a strong influence on WhatsApp exits in the open-source library named libpl_droidsonroids_gif.so, which is a part of the android-gif-drawable package and is used by numerous Android applications when processing the GIF files.

UPDATE AND UPGRADE

On the contrary, the flaw can be avoided by safety measures. Having vulnerability can put Android users to risk. Attackers can abuse the above-mentioned flaw to take control of user’s devices. Hence, developers are urged to upgrade the source library to reduce the risk.

Tags:
aiden
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

Related Tutorials in GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

How to Install Android Emulator on Ubuntu 20.4.1
How to Install Android Emulator on Ubuntu 20.4.1
Jul 13, 2021
How to install Android emulator in Ubuntu 16.04
How to install Android emulator in Ubuntu 16.04
Dec 30, 2017
How to Setup Genymotion Android Emulator 2.11.0 in Linux Mint 18.3
How to Setup Genymotion Android Emulator 2.11.0 in Linux Mint 18.3
Apr 23, 2018

Related Forums in GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

Related Forums in GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

Linux
oliver class=
How to run the android apps in linux
Mar 2, 2017
Web application
luke class=
how to run android application in linux
May 16, 2017

Related News in GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

Related News in GIF PROCESSING VULNERABILITY THWAKING ANDROID APPLICATIONS OTHER THAN WHATSAPP

Anbox, the Android-to-Linux tool the developers have been waiting for
Anbox, the Android-to-Linux tool the developers have been waiting for
Apr 17, 2017
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
Mar 13, 2019
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
Google is imperative in bringing Linux Kernel versions in Android Oreo
Google is imperative in bringing Linux Kernel versions in Android Oreo
Sep 4, 2017
Use your Samsung Android phone as your Linux desktop now
Use your Samsung Android phone as your Linux desktop now
Oct 20, 2017
Magecart Targets OpenCart Websites Payment Information
Magecart Targets OpenCart Websites Payment Information
May 17, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Isaac ?
How to run windows application in linux

I need to run the windows application in my Linux machine, instead of installing from yum repo or any other repos. How to do that..??

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.