← Back

CVE-2020-27853

nvd nist
Published: Oct 27, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Wire before 2020-10-16 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a format string. This affects Wire AVS (Audio, Video, and Signaling) 5.3 through 6.x before 6.4, the Wire Secure Messenger application before 3.49.918 for Android, and the Wire Secure Messenger application before 3.61 for iOS. This occurs via the value parameter to sdp_media_set_lattr in peerflow/sdp.c.

Affected (6)

3 products
Wire
Wire Audio, Video, And Signaling
Wire Secure Messenger
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Wire
Before 3.21.2936
Before 3.21.3959
Before 3.21.3932
From 5.3 to 6.4
Wire
Before 3.49.918
Before 3.61

References (4)

Timeline

No history available yet.