CVE-2018-11871: Buffer Overflow
Buffer overwrite can happen in WLAN function while processing set pdev parameter command due to lack of input validation in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version IPQ4019, IPQ8064, IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MSM8996AU, QCA6174A, QCA6564, QCA6574, QCA6574AU, QCA6584, QCA6584AU, QCA9377, QCA9378, QCA9379, QCA9531, QCA9558, QCA9563, QCA9880, QCA9886, QCA9980, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 600, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDM630, SDM632, SDM636, SDM660, SDM710, SDX20, SnapdragonHighMed2016.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11871?
CVE-2018-11871 has been classified with a high severity due to the potential for buffer overwrite in vulnerable devices.
How do I fix CVE-2018-11871?
To fix CVE-2018-11871, update the firmware of your affected Qualcomm hardware to the latest version that addresses this vulnerability.
Which devices are affected by CVE-2018-11871?
CVE-2018-11871 affects a range of Qualcomm devices including Snapdragon Automotive and Mobile platforms like IPQ4019, IPQ8064, and MDM series.
Can CVE-2018-11871 lead to remote code execution?
Yes, CVE-2018-11871 can potentially allow attackers to execute arbitrary code remotely due to the buffer overwrite vulnerability.
Is CVE-2018-11871 limited to Android devices only?
No, while CVE-2018-11871 affects some Android devices, it also impacts other platforms using Qualcomm chipsets.