First published: Mon Apr 02 2018(Updated: )
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 435, SD 617, SD 625, and Snapdragon_High_Med_2016, binary Calibration files under data/misc/audio have 777 permissions.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm MDM9615 firmware | ||
Qualcomm MDM9615 | ||
Qualcomm MDM9625 firmware | ||
Qualcomm MDM9625 | ||
Qualcomm MDM9635M firmware | ||
Qualcomm MDM9635M | ||
qualcomm mdm9640 firmware | ||
qualcomm MDM9640 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm MDM9650 | ||
qualcomm SD 210 firmware | ||
qualcomm SD 210 | ||
qualcomm SD 212 firmware | ||
qualcomm SD 212 | ||
qualcomm SD 205 firmware | ||
qualcomm SD 205 | ||
qualcomm SD 400 firmware | ||
qualcomm SD 400 | ||
qualcomm SD 425 firmware | ||
qualcomm SD 425 | ||
Qualcomm SD 430 firmware | ||
Qualcomm SD 430 | ||
Qualcomm SD 435 firmware | ||
Qualcomm SD 435 | ||
qualcomm sd 617 firmware | ||
Qualcomm QCA617 | ||
qualcomm SD 625 firmware | ||
qualcomm SD 625 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-10057 is a vulnerability in Android devices that have not been updated with the April 2018 security patch or earlier.
CVE-2014-10057 has a severity rating of 9.8, which is considered critical.
Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, MDM9640, MDM9650, SD 210/SD 212/SD 205, SD 400, SD 425, SD 430, SD 435, SD 617, and SD 625 devices are affected by CVE-2014-10057.
The vulnerability in CVE-2014-10057 allows unauthorized access to binary Calibration files under data/misc/audio on affected Android devices.
To fix CVE-2014-10057, you should update your Android device to the April 2018 security patch or a later version.