CVE-2018-11285: Critical severity Google Android vulnerability
In Snapdragon (Automobile, Mobile, Wear) in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, SnapdragonHighMed2016, while parsing FLAC file with corrupted picture block, a buffer over-read can occur.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11285?
The severity of CVE-2018-11285 is critical with a CVSS score of 7.8.
Which software are affected by CVE-2018-11285?
CVE-2018-11285 affects Snapdragon (Automobile, Mobile, Wear) in various versions, including MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, and SDM710.
Where can I find more information about CVE-2018-11285?
You can find more information about CVE-2018-11285 at the following references:
What is the Common Weakness Enumeration (CWE) of CVE-2018-11285?
The Common Weakness Enumeration (CWE) of CVE-2018-11285 is CWE-125.
How can I mitigate CVE-2018-11285?
To mitigate CVE-2018-11285, it is recommended to apply the necessary security patches provided by the vendor or follow the guidelines provided in the references.