« Volver al listado

CVE-2020-1903

Estado: ModificadaMedia (5.5)—

An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-1903",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve-assign@fb.com",
      "affectedData": [
        {
          "vendor": "Facebook",
          "product": "WhatsApp for iOS",
          "versions": [
            {
              "status": "affected",
              "version": "2.20.61"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.20.61",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Facebook",
          "product": "WhatsApp Business for iOS",
          "versions": [
            {
              "status": "affected",
              "version": "2.20.61"
            },
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "2.20.61",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-10-06T18:15:15.907",
  "references": [
    {
      "url": "https://www.whatsapp.com/security/advisories/2020/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve-assign@fb.com"
    },
    {
      "url": "https://www.whatsapp.com/security/advisories/2020/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-assign@fb.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicitly open the attachment if it was received from a number not in the receiver's WhatsApp contacts."
    },
    {
      "lang": "es",
      "value": "Un problema al descomprimir documentos docx, pptx y xlsx en WhatsApp para iOS anterior a versión v2.20.61 y WhatsApp Business para iOS anterior a versión v2.20.61, podría haber resultado en una denegación de servicio por falta de memoria. Este problema habría requerido que el receptor abriera explícitamente el archivo adjunto si se recibió de un número que no estaba en los contactos de WhatsApp del receptor"
    }
  ],
  "lastModified": "2026-06-17T03:02:35.223",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:whatsapp:whatsapp:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51FFA80F-58E2-4EBB-9815-6DFCFABE6F6A",
              "versionEndExcluding": "2.20.61"
            },
            {
              "criteria": "cpe:2.3:a:whatsapp:whatsapp_business:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73A2E8EB-9428-48E6-AB28-3B3A3FD838EF",
              "versionEndExcluding": "2.20.61"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-assign@fb.com"
}