PT-2019-11892 · Qualcomm · Qualcomm Snapdragon Wired Infrastructure/Networking+10

Published

2019-09-30

·

Updated

2019-10-02

·

CVE-2019-10499

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Qualcomm Snapdragon Mobile versions prior to the fixed version Qualcomm Snapdragon Voice & Music versions prior to the fixed version Qualcomm Snapdragon Wired Infrastructure and Networking versions prior to the fixed version Qualcomm IPQ4019 versions prior to the fixed version Qualcomm IPQ8064 versions prior to the fixed version Qualcomm IPQ8074 versions prior to the fixed version Qualcomm QCS405 versions prior to the fixed version Qualcomm SD 665 versions prior to the fixed version Qualcomm SD 675 versions prior to the fixed version Qualcomm SD 730 versions prior to the fixed version Qualcomm SD 855 versions prior to the fixed version
Description The issue arises from improper validation of read and write index of tx and rx fifos before using them for data copy from fifo, leading to out-of-bound access.
Recommendations For Qualcomm Snapdragon Mobile, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Voice & Music, update to a version that includes the fix for this issue. For Qualcomm Snapdragon Wired Infrastructure and Networking, update to a version that includes the fix for this issue. For Qualcomm IPQ4019, update to a version that includes the fix for this issue. For Qualcomm IPQ8064, update to a version that includes the fix for this issue. For Qualcomm IPQ8074, update to a version that includes the fix for this issue. For Qualcomm QCS405, update to a version that includes the fix for this issue. For Qualcomm SD 665, update to a version that includes the fix for this issue. For Qualcomm SD 675, update to a version that includes the fix for this issue. For Qualcomm SD 730, update to a version that includes the fix for this issue. For Qualcomm SD 855, update to a version that includes the fix for this issue.

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10499

Affected Products

Qualcomm Ipq4019
Qualcomm Ipq8064
Qualcomm Ipq8074
Qualcomm Qcs405
Qualcomm Sd 665
Qualcomm Sd 675
Qualcomm Sd 730
Qualcomm Sd 855
Qualcomm Snapdragon Mobile
Qualcomm Snapdragon Voice & Music
Qualcomm Snapdragon Wired Infrastructure/Networking