Vulnerabilities > CVE-2019-11419 - NULL Pointer Dereference vulnerability in Tencent Wechat

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
tencent
CWE-476
exploit available

Summary

vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf file. The content of the replacement must be derived from the phone's IMEI. The crash occurs upon receiving a message that contains the replaced emoji.

Common Weakness Enumeration (CWE)

Exploit-Db

fileexploits/android/dos/46853.txt
idEDB-ID:46853
last seen2019-05-16
modified2019-05-16
platformandroid
port
published2019-05-16
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/46853
titleWeChat for Android 7.0.4 - 'vcodec2_hls_filter' Denial of Service
typedos