First published: Tue Sep 04 2018(Updated: )
When processing IE set command, buffer overwrite may occur due to lack of input validation of the IE length in Snapdragon Mobile in version SD 835, SD 845, SD 850.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Android | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SDA845 Firmware | ||
Qualcomm SD845 | ||
Qualcomm SD850 Firmware | ||
Qualcomm SD850 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11858 is a critical vulnerability due to potential buffer overwrite in Qualcomm Snapdragon mobile devices.
To fix CVE-2018-11858, update the firmware of Qualcomm Snapdragon 835, 845, or 850 to the latest version provided by Qualcomm.
CVE-2018-11858 affects devices using Qualcomm Snapdragon 835, 845, and 850 firmware.
CVE-2018-11858 is a buffer overwrite vulnerability caused by inadequate input validation.
No, CVE-2018-11858 specifically affects Qualcomm Snapdragon 835, 845, and 850, not all Snapdragon devices.