PT-2018-17209 · Qualcomm · Sdx20+18

Published

2018-11-28

·

Updated

2018-12-26

·

CVE-2018-5877

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon versions MDM9206, MDM9607, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 600, SD 820, SD 820A, SD 835, SDA660, SDX20
Description: A string in the device programmer target-side code for firehose may not be properly NULL terminated, leading to an incorrect buffer size. This issue affects Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear.
Recommendations: For versions MDM9206, MDM9607, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 600, SD 820, SD 820A, SD 835, SDA660, SDX20, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-5877

Affected Products

Mdm9206
Mdm9607
Mdm9640
Mdm9650
Mdm9655
Msm8909W
Msm8996Au
Sd 205
Sd 210
Sd 212
Sd 600
Sd 820
Sd 820A
Sd 835
Sda660
Sdx20
Snapdragon Automobile
Snapdragon Mobile
Snapdragon Wear