First published: Tue Sep 04 2018(Updated: )
Crafted Binder Request Causes Heap UAF in MediaServer
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
All of | ||
Qualcomm 9206 LTE Firmware | ||
Qualcomm 9206 LTE | ||
All of | ||
qualcomm apq8016 firmware | ||
qualcomm apq8016 | ||
All of | ||
Qualcomm apq8017 firmware | ||
Qualcomm apq8017 | ||
All of | ||
Qualcomm APQ8039 Firmware | ||
Qualcomm APQ8039 Firmware | ||
All of | ||
qualcomm apq8052 firmware | ||
qualcomm apq8052 | ||
All of | ||
qualcomm apq8056 firmware | ||
qualcomm apq8056 | ||
All of | ||
qualcomm apq8076 firmware | ||
qualcomm apq8076 | ||
All of | ||
Qualcomm aqt1000 firmware | ||
Qualcomm aqt1000 | ||
All of | ||
qualcomm ar6003 firmware | ||
qualcomm ar6003 | ||
All of | ||
Qualcomm sd660 firmware | ||
Qualcomm sd660 | ||
All of | ||
qualcomm sd670 firmware | ||
qualcomm sd670 | ||
All of | ||
qualcomm sd820 Firmware | ||
qualcomm sd820 | ||
All of | ||
qualcomm sd821 firmware | ||
qualcomm sd821 | ||
All of | ||
Qualcomm sd835 firmware | ||
Qualcomm sd835 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11816 has a high severity level due to the potential for remote code execution vulnerabilities.
To fix CVE-2018-11816, ensure your device's firmware is updated to the latest version provided by the manufacturer.
CVE-2018-11816 affects various versions of Android and specific Qualcomm firmware products.
Yes, CVE-2018-11816 can potentially be exploited remotely if the conditions are met.
The impact of CVE-2018-11816 includes the possibility of arbitrary code execution which can lead to further compromise of the affected system.