PT-2018-1251 · Qualcomm+1 · Qualcomm Snapdragon Mobile Mdm9625+4
Publicado
2018-04-02
·
Atualizado
2018-05-01
·
CVE-2015-9215
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2018-04-05 security patch level
Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810 (affected versions not specified)
Description
The issue is related to the
find ep() function in the Qualcomm USB Bootloader component of the Android operating system, which is vulnerable to a null pointer dereference. This could allow a remote attacker to impact the confidentiality, integrity, and availability of protected information. The vulnerability is caused by improper input validation.Recommendations
For Android versions prior to 2018-04-05 security patch level, update to a version with a security patch level of 2018-04-05 or later.
For Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, and SD 810, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Android
Qualcomm Snapdragon Mobile Mdm9615
Qualcomm Snapdragon Mobile Mdm9625
Qualcomm Snapdragon Mobile Mdm9635M
Sd 810