CVE-2014-10043: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800, while reading PlayReady rights string information from command buffer (which is sent from non-secure side), if length of rights string is very large, a buffer over read occurs, exposing TZ App memory to non-secure side.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2014-10043?
CVE-2014-10043 is a vulnerability in Android devices before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, and SD 800.
How severe is CVE-2014-10043?
CVE-2014-10043 has a severity rating of 7.5, which is considered high.
What is the affected software by CVE-2014-10043?
The affected software by CVE-2014-10043 includes Google Android, Qualcomm MSM8909W Firmware, Qualcomm SD 210 Firmware, Qualcomm SD 212 Firmware, Qualcomm SD 205 Firmware, Qualcomm SD 400 Firmware, Qualcomm SD 410 Firmware, Qualcomm SD 412 Firmware, and Qualcomm SD 800 Firmware.
How does CVE-2014-10043 exploit work?
CVE-2014-10043 exploits a vulnerability where PlayReady rights string information is read from a command buffer sent from non-secure side, allowing for potential unauthorized access.
Are there any fixes available for CVE-2014-10043?
Yes, the fix for CVE-2014-10043 is included in the security patch level update released on 2018-04-05.