CVE-2018-11870: Buffer Overflow
Buffer overwrite can occur when the legacy rates count received from the host is not checked against the maximum number of legacy rates in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA4531, QCA6174A, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, SD 210/SD 212/SD 205, SD 425, SD 600, SD 625, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDX20.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11870?
CVE-2018-11870 is a vulnerability that allows buffer overwrite when the legacy rates count received from the host is not checked against the maximum number of legacy rates.
Which software is affected by CVE-2018-11870?
Qualcomm Mdm9206 Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9650 Firmware, and Google Android are affected by CVE-2018-11870.
What is the severity of CVE-2018-11870?
CVE-2018-11870 has a severity rating of 7.8, which is considered high.
How can I fix CVE-2018-11870?
To fix CVE-2018-11870, update to the latest firmware or software version provided by Qualcomm or Google, depending on the affected product.
Where can I find more information about CVE-2018-11870?
You can find more information about CVE-2018-11870 in the following references: [SecurityFocus](http://www.securityfocus.com/bid/107681), [Qualcomm Product Security Bulletins](https://www.qualcomm.com/company/product-security/bulletins), and [Android Security Bulletin](https://source.android.com/docs/security/bulletin/2019-04-01/#asterisk).