PT-2018-4673 · Qualcomm+1 · Sd 808+31

Publicado

2018-04-18

·

Atualizado

2018-05-01

·

CVE-2016-10437

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to 2018-04-05
Description The issue concerns information exposure when logging debug statements or ftrace events from rmnet data. Specifically, the socket buffer function uses normal format specifiers, which may lead to information exposure. This affects various Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear products, including FSM9055, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20.
Recommendations For Android versions prior to 2018-04-05, consider restricting access to debug logs and ftrace events to minimize the risk of information exposure until a patch is available.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-10437

Produtos afetados

Android
Fsm9055
Mdm9206
Mdm9607
Mdm9635M
Mdm9640
Mdm9650
Msm8909W
Qualcomm Small Cell Soc
Sd 205
Sd 210
Sd 212
Sd 400
Sd 410
Sd 412
Sd 415
Sd 425
Sd 430
Sd 450
Sd 615
Sd 616
Sd 617
Sd 625
Sd 650
Sd 652
Sd 808
Sd 810
Sd 820
Sd 835
Sdx20
Snapdragon Mobile
Snapdragon Wear