CVE-2018-16132

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
29/08/2018
Last modified:
08/11/2018

Description

The image rendering component (createGenericPreview) of the Open Whisper Signal app through 2.29.0 for iOS fails to check for unreasonably large images before manipulating received images. This allows for a large image sent to a user to exhaust all available memory when the image is displayed, resulting in a forced restart of the device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:signal:signal:*:*:*:*:*:iphone_os:*:* 2.29.0 (including)


References to Advisories, Solutions, and Tools