Lucene search

K
symantecSymantec Security ResponseSMNTC-110291
HistorySep 27, 2019 - 12:00 a.m.

WhatsApp CVE-2019-11927 Integer Overflow Vulnerability

2019-09-2700:00:00
Symantec Security Response
www.symantec.com
18

EPSS

0.003

Percentile

65.9%

Description

WhatsApp is prone to an integer overflow vulnerability. Attackers can exploit this issue to cause denial-of-service conditions. Due to the nature of this issue, arbitrary code-execution may be possible; however this has not been confirmed.

Technologies Affected

  • WhatsApp Inc. WhatsApp for Android 2.18.225
  • WhatsApp Inc. WhatsApp for Android 2.18.239
  • WhatsApp Inc. WhatsApp for Android 2.18.247
  • WhatsApp Inc. WhatsApp for Android 2.18.248
  • WhatsApp Inc. WhatsApp for Android 2.18.257
  • WhatsApp Inc. WhatsApp for Android 2.18.264
  • WhatsApp Inc. WhatsApp for Android 2.18.267
  • WhatsApp Inc. WhatsApp for Android 2.18.273
  • WhatsApp Inc. WhatsApp for Android 2.18.276
  • WhatsApp Inc. WhatsApp for Android 2.19.133
  • WhatsApp Inc. WhatsApp for Android 2.19.134
  • WhatsApp Inc. WhatsApp for iOS 2.18.100.6
  • WhatsApp Inc. WhatsApp for iOS 2.18.81
  • WhatsApp Inc. WhatsApp for iOS 2.18.90.24
  • WhatsApp Inc. WhatsApp for iOS 2.19.50
  • WhatsApp Inc. WhatsApp for iOS 2.19.51

Recommendations

Deploy network intrusion detection systems to monitor network traffic for malicious activity.
Deploy NIDS to monitor network traffic for signs of anomalous or suspicious activity. This includes but is not limited to requests that include NOP sleds and unexplained incoming and outgoing traffic. This may indicate exploit attempts or activity that results from a successful exploit.

Implement multiple redundant layers of security.
Various memory-protection schemes (such as nonexecutable and randomly mapped memory segments) may hinder an attacker’s ability to exploit this vulnerability.

Updates are available. Please see the references or vendor advisory for more information.

EPSS

0.003

Percentile

65.9%

Related for SMNTC-110291