PT-2018-4673 · Qualcomm+1 · Sd 808+31

Published

2018-04-18

·

Updated

2018-05-01

·

CVE-2016-10437

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Android versions prior to 2018-04-05
Description The issue concerns information exposure when logging debug statements or ftrace events from rmnet data. Specifically, the socket buffer function uses normal format specifiers, which may lead to information exposure. This affects various Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear products, including FSM9055, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20.
Recommendations For Android versions prior to 2018-04-05, consider restricting access to debug logs and ftrace events to minimize the risk of information exposure until a patch is available.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-10437

Affected Products

Android
Fsm9055
Mdm9206
Mdm9607
Mdm9635M
Mdm9640
Mdm9650
Msm8909W
Qualcomm Small Cell Soc
Sd 205
Sd 210
Sd 212
Sd 400
Sd 410
Sd 412
Sd 415
Sd 425
Sd 430
Sd 450
Sd 615
Sd 616
Sd 617
Sd 625
Sd 650
Sd 652
Sd 808
Sd 810
Sd 820
Sd 835
Sdx20
Snapdragon Mobile
Snapdragon Wear