PT-2018-4673 · Qualcomm+1 · Sd 808+31
Published
2018-04-18
·
Updated
2018-05-01
·
CVE-2016-10437
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Android versions prior to 2018-04-05
Description
The issue concerns information exposure when logging debug statements or ftrace events from
rmnet data. Specifically, the socket buffer function uses normal format specifiers, which may lead to information exposure. This affects various Qualcomm Small Cell SoC, Snapdragon Mobile, and Snapdragon Wear products, including FSM9055, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 835, and SDX20.Recommendations
For Android versions prior to 2018-04-05, consider restricting access to debug logs and ftrace events to minimize the risk of information exposure until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Fsm9055
Mdm9206
Mdm9607
Mdm9635M
Mdm9640
Mdm9650
Msm8909W
Qualcomm Small Cell Soc
Sd 205
Sd 210
Sd 212
Sd 400
Sd 410
Sd 412
Sd 415
Sd 425
Sd 430
Sd 450
Sd 615
Sd 616
Sd 617
Sd 625
Sd 650
Sd 652
Sd 808
Sd 810
Sd 820
Sd 835
Sdx20
Snapdragon Mobile
Snapdragon Wear