PT-2019-8784 · Qualcomm · Snapdragon Wired Infrastructure/Networking+8

Published

2019-02-25

·

Updated

2019-02-28

·

CVE-2018-11289

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Snapdragon Auto versions IPQ8074 Snapdragon Compute versions MDM9150 Snapdragon Connectivity versions MDM9206 Snapdragon Consumer Electronics Connectivity versions MDM9607 Snapdragon Consumer IOT versions MDM9650 Snapdragon Industrial IOT versions MDM9655 Snapdragon Mobile versions MSM8996AU Snapdragon Voice & Music versions QCA8081 Snapdragon Wired Infrastructure and Networking versions QCS605 Snapdragon versions SD 210/SD 212/SD 205 Snapdragon versions SD 410/12 Snapdragon versions SD 425 Snapdragon versions SD 427 Snapdragon versions SD 430 Snapdragon versions SD 435 Snapdragon versions SD 439 / SD 429 Snapdragon versions SD 450 Snapdragon versions SD 625 Snapdragon versions SD 632 Snapdragon versions SD 636 Snapdragon versions SD 650/52 Snapdragon versions SD 675 Snapdragon versions SD 712 / SD 710 / SD 670 Snapdragon versions SD 820 Snapdragon versions SD 820A Snapdragon versions SD 835 Snapdragon versions SD 845 / SD 850 Snapdragon versions SD 8CX Snapdragon versions SDA660 Snapdragon versions SDM439 Snapdragon versions SDM630 Snapdragon versions SDM660 Snapdragon High Med 2016 versions SXR1130
Description Data truncation during higher to lower type conversion can cause less memory allocation than desired, leading to a buffer overflow in various Snapdragon products.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-11289

Affected Products

Snapdragon Auto
Snapdragon Compute
Snapdragon Connectivity
Snapdragon Consumer Electronics Connectivity
Snapdragon Consumer Iot
Snapdragon Industrial Iot
Snapdragon Mobile
Snapdragon Voice & Music
Snapdragon Wired Infrastructure/Networking