CVE-2014-9998: Buffer Overflow
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 625, SD 808, SD 810, SD 820, and SDX20, while processing firmware image signature, the internal buffer may overflow if the firmware signature size is large.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9998?
The severity of CVE-2014-9998 is critical with a severity score of 9.8.
Which devices are affected by CVE-2014-9998?
Devices running Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear IPQ4019, IPQ8064, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9558, QCA9880, and QCA9886 firmware are affected by CVE-2014-9998.
How can I fix CVE-2014-9998?
You can fix CVE-2014-9998 by updating your Android device to a security patch level released on or after 2018-04-05.
What is the Common Weakness Enumeration (CWE) ID for CVE-2014-9998?
The CWE ID for CVE-2014-9998 is 119.
Where can I find more information about CVE-2014-9998?
You can find more information about CVE-2014-9998 at the following references: [1](http://www.securityfocus.com/bid/103671), [2](https://source.android.com/security/bulletin/2018-04-01), [3](https://source.android.com/docs/security/bulletin/2018-04-01/#asterisk)