Heap Overflow Vulnerability in Instagram for Android by Facebook
CVE-2020-1895

7.8HIGH

Key Information:

Vendor

Facebook

Vendor
CVE Published:
9 April 2020

What is CVE-2020-1895?

A heap overflow vulnerability has been identified in Instagram for Android, which can be triggered when a user attempts to upload an image with non-standard dimensions. This flaw affects all versions of the application prior to 128.0.0.26.128, potentially leading to unexpected application behavior or crashes. It highlights the importance of validating input dimensions during image uploads to prevent exploitation.

Affected Version(s)

Instagram for Android < 128.0.0.26.128

Instagram for Android 128.0.0.26.128

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-1895 : Heap Overflow Vulnerability in Instagram for Android by Facebook