{"id":"CVE-2019-11932","aliases":["GHSA-x534-j49x-mqvj"],"url":"https://o3.security/vulnerability/CVE-2019-11932","summary":"android-gif-drawable Double Free vulnerability","details":"A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.","published":"2019-10-03T22:15:10.370Z","modified":"2026-07-08T15:55:08.171721Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":25,"affectedPackages":[{"ecosystem":"Maven","name":"pl.droidsonroids.gif:android-gif-drawable","fixedVersion":"1.2.18"}],"fix":{"url":"https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20","label":"koral--/android-gif-drawable@cc5b4f8"},"references":[{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/154867/Whatsapp-2.19.216-Remote-Code-Execution.html"},{"type":"ADVISORY","url":"http://packetstormsecurity.com/files/158306/WhatsApp-android-gif-drawable-Double-Free.html"},{"type":"ADVISORY","url":"http://seclists.org/fulldisclosure/2019/Nov/27"},{"type":"ADVISORY","url":"https://gist.github.com/wdormann/874198c1bd29c7dd2157d9fc1d858263"},{"type":"ADVISORY","url":"https://github.com/koral--/android-gif-drawable/pull/673"},{"type":"ADVISORY","url":"https://github.com/koral--/android-gif-drawable/pull/673/commits/4944c92761e0a14f04868cbcf4f4e86fd4b7a4a9"},{"type":"ADVISORY","url":"https://www.facebook.com/security/advisories/cve-2019-11932"},{"type":"FIX","url":"https://github.com/koral--/android-gif-drawable/commit/cc5b4f8e43463995a84efd594f89a21f906c2d20"},{"type":"EVIDENCE","url":"https://awakened1712.github.io/hacking/hacking-whatsapp-gif-rce/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T15:55:08.171721Z"}}