PT-2020-9535 · Qualcomm+1 · Snapdragon+1

Published

2020-07-30

·

Updated

2021-07-21

·

CVE-2019-14123

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Qualcomm Snapdragon versions (affected versions not specified)
Description: The issue is related to a possible buffer overflow and over read due to missing bounds checks for fixed limits. This occurs when considering the Widevine HLOS client as non-trustable in various Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking, across several chipsets such as Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, and SXR2130.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Memory Corruption

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14123

Affected Products

Snapdragon
Widevine Hlos