Out-of-bound access will occur in USB driver due to lack of check to validate the frame size passed by user in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9607, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, QCS605, SDX24
References
Link | Resource |
---|---|
https://www.qualcomm.com/company/product-security/bulletins/january-2020-bulletin | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
History
No history.
Information
Published : 2020-01-21 07:15
Updated : 2020-01-24 13:52
NVD link : CVE-2019-10606
Mitre link : CVE-2019-10606
CVE.ORG link : CVE-2019-10606
JSON object : View
Products Affected
qualcomm
- mdm9607
- msm8940_firmware
- qcs605_firmware
- msm8920_firmware
- msm8937
- mdm9607_firmware
- msm8909w_firmware
- msm8909w
- msm8917
- msm8937_firmware
- sdx24_firmware
- sdx24
- msm8940
- msm8920
- qcs605
- msm8917_firmware
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')