CVE-2017-18324: Infoleak
Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, SD 855, SDX24, SnapdragonHighMed2016.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-18324?
CVE-2017-18324 is a vulnerability that allows cryptographic key material to be leaked in debug messages in GERAN in Snapdragon mobile and Snapdragon Wear devices.
What is the severity of CVE-2017-18324?
The severity of CVE-2017-18324 is high.
Which devices are affected by CVE-2017-18324?
Devices affected by CVE-2017-18324 include Snapdragon mobile and Snapdragon Wear devices running MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650, SD 652, SD 800, SD 810, SD 820, SD 835, SD 855, SDX24, and Qualcomm Snapdragon High Med 2016 firmware versions.
How do I fix CVE-2017-18324?
To fix CVE-2017-18324, it is recommended to update your firmware to the latest version provided by the device manufacturer.
Where can I find more information about CVE-2017-18324?
You can find more information about CVE-2017-18324 at the following references: [Reference 1](https://source.android.com/docs/security/bulletin/2018-12-01/#asterisk), [Reference 2](https://source.android.com/docs/security/bulletin/2018-12-01), [Reference 3](http://www.securityfocus.com/bid/106128)