CVE-2019-17192
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing
The WebRTC component in the Signal Private Messenger application through 4.47.7 for Android processes videoconferencing RTP packets before a callee chooses to answer a call, which might make it easier for remote attackers to cause a denial of service or possibly have unspecified other impact via malformed packets. NOTE: the vendor plans to continue this behavior for performance reasons unless a WebRTC design change occurs.
CRITICAL · CVSS 9.8
EPSS 0.01152
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0