PT-2019-11892 · Qualcomm · Qualcomm Snapdragon Wired Infrastructure/Networking+10
Published
2019-09-30
·
Updated
2019-10-02
·
CVE-2019-10499
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Qualcomm Snapdragon Mobile versions prior to the fixed version
Qualcomm Snapdragon Voice & Music versions prior to the fixed version
Qualcomm Snapdragon Wired Infrastructure and Networking versions prior to the fixed version
Qualcomm IPQ4019 versions prior to the fixed version
Qualcomm IPQ8064 versions prior to the fixed version
Qualcomm IPQ8074 versions prior to the fixed version
Qualcomm QCS405 versions prior to the fixed version
Qualcomm SD 665 versions prior to the fixed version
Qualcomm SD 675 versions prior to the fixed version
Qualcomm SD 730 versions prior to the fixed version
Qualcomm SD 855 versions prior to the fixed version
Description
The issue arises from improper validation of read and write index of tx and rx fifos before using them for data copy from fifo, leading to out-of-bound access.
Recommendations
For Qualcomm Snapdragon Mobile, update to a version that includes the fix for this issue.
For Qualcomm Snapdragon Voice & Music, update to a version that includes the fix for this issue.
For Qualcomm Snapdragon Wired Infrastructure and Networking, update to a version that includes the fix for this issue.
For Qualcomm IPQ4019, update to a version that includes the fix for this issue.
For Qualcomm IPQ8064, update to a version that includes the fix for this issue.
For Qualcomm IPQ8074, update to a version that includes the fix for this issue.
For Qualcomm QCS405, update to a version that includes the fix for this issue.
For Qualcomm SD 665, update to a version that includes the fix for this issue.
For Qualcomm SD 675, update to a version that includes the fix for this issue.
For Qualcomm SD 730, update to a version that includes the fix for this issue.
For Qualcomm SD 855, update to a version that includes the fix for this issue.
Fix
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qualcomm Ipq4019
Qualcomm Ipq8064
Qualcomm Ipq8074
Qualcomm Qcs405
Qualcomm Sd 665
Qualcomm Sd 675
Qualcomm Sd 730
Qualcomm Sd 855
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Voice & Music
Qualcomm Snapdragon Wired Infrastructure/Networking