android-gif-drawable Double Free vulnerability
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 13, 2025
Package
Affected versions
< 1.2.18
Patched versions
1.2.18
Description
Published by the National Vulnerability Database
Oct 3, 2019
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jan 13, 2025
Last updated
Jan 13, 2025
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
References