PT-2020-9535 · Qualcomm+1 · Snapdragon+1
Published
2020-07-30
·
Updated
2021-07-21
·
CVE-2019-14123
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Qualcomm Snapdragon versions (affected versions not specified)
Description:
The issue is related to a possible buffer overflow and over read due to missing bounds checks for fixed limits. This occurs when considering the Widevine HLOS client as non-trustable in various Snapdragon products, including Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking, across several chipsets such as Kamorta, QCS404, Rennell, SC7180, SDX55, SM6150, SM7150, SM8250, and SXR2130.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Out of bounds Read
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Snapdragon
Widevine Hlos