← Back

CVE-2021-24043

nvd nist
Published: Feb 2, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A missing bound check in RTCP flag parsing code prior to WhatsApp for Android v2.21.23.2, WhatsApp Business for Android v2.21.23.2, WhatsApp for iOS v2.21.230.6, WhatsApp Business for iOS 2.21.230.7, and WhatsApp Desktop v2.2145.0 could have allowed an out-of-bounds heap read if a user sent a malformed RTCP packet during an established call.

Affected (5)

2 products
Whatsapp
Whatsapp Business
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Whatsapp
Version 2.21.23.2
Version 2.21.230.6
Version 2.2145.0
Whatsapp
Version 2.21.23.2
Version 2.21.230.7

References (3)

Source: cve-assign@fb.com
Not ApplicableVendor Advisory
Source: nvd@nist.gov
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Not ApplicableVendor Advisory

Timeline

No history available yet.