Description
The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7987 | The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device. |
References
| Link | Providers |
|---|---|
| http://seclists.org/bugtraq/2018/Aug/57 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:17:38.165Z
Reserved: 2018-08-29T00:00:00.000Z
Link: CVE-2018-16132
No data.
Status : Modified
Published: 2018-08-29T22:29:00.353
Modified: 2024-11-21T03:52:07.783
Link: CVE-2018-16132
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD