First published: Tue Sep 04 2018(Updated: )
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, Snapdragon_High_Med_2016, while parsing FLAC file with corrupted picture block, a buffer over-read can occur.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm 8909 Firmware | ||
Qualcomm Snapdragon 8909 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 212 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm 205 Firmware | ||
Qualcomm Snapdragon 205 | ||
Qualcomm SD425 Firmware | ||
Qualcomm Snapdragon 425 | ||
Qualcomm SD 427 firmware | ||
Qualcomm SD427 Firmware | ||
Qualcomm SD 430 Firmware | ||
Qualcomm Snapdragon 430 | ||
Qualcomm Snapdragon 435 Firmware | ||
Qualcomm Snapdragon 435 | ||
Qualcomm SD 450 Firmware | ||
Qualcomm Snapdragon 450 | ||
Qualcomm SD 615 Firmware | ||
Qualcomm Snapdragon 615 | ||
Qualcomm Snapdragon 616 firmware | ||
Qualcomm Snapdragon 616 firmware | ||
Qualcomm Snapdragon 415 Firmware | ||
Qualcomm Snapdragon 415 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SD 650 Firmware | ||
Qualcomm Snapdragon 650 | ||
Qualcomm Snapdragon 810 Firmware | ||
Qualcomm Snapdragon 810 | ||
Qualcomm SD 820 Firmware | ||
Qualcomm Snapdragon 820 | ||
Qualcomm SD 820A firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm Snapdragon 845 | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SDM429W | ||
Qualcomm SD429 | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM439 Firmware | ||
Qualcomm SDM630 | ||
Qualcomm SDM630 Firmware | ||
Qualcomm SDM632 Firmware | ||
Qualcomm SDM632 Firmware | ||
Qualcomm SD 636 Firmware | ||
Qualcomm SDM636 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 | ||
Qualcomm SD 710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SDX20 Firmware | ||
Qualcomm SDX20 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-11285 is critical with a CVSS score of 7.8.
CVE-2018-11285 affects Snapdragon (Automobile, Mobile, Wear) in various versions, including MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, and SDM710.
You can find more information about CVE-2018-11285 at the following references:
The Common Weakness Enumeration (CWE) of CVE-2018-11285 is CWE-125.
To mitigate CVE-2018-11285, it is recommended to apply the necessary security patches provided by the vendor or follow the guidelines provided in the references.