PT-2016-7037 · Qualcomm · Qualcomm Wi-Fi Driver
Published
2016-10-10
·
Updated
2016-12-06
·
CVE-2016-6676
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Qualcomm Wi-Fi driver versions prior to 2016-10-05
Description
The issue is related to an off-by-one error in the CORE/HDD/src/wlan hdd cfg.c file of the Qualcomm Wi-Fi driver. This error can be exploited by attackers via a crafted application that makes a GET CFG ioctl call, potentially leading to a buffer overflow. As a result, attackers may gain privileges or cause a denial of service.
Recommendations
For versions prior to 2016-10-05, update the Qualcomm Wi-Fi driver to a version released after 2016-10-05 to resolve the issue. As a temporary workaround, consider restricting access to the wlan hdd cfg.c file or disabling the GET CFG ioctl call functionality until a patch is available.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qualcomm Wi-Fi Driver