CVE-2018-13887: Integer Overflow
Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8909W, QCS605, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 600, SD 625, SD 632, SD 636, SD 675, SD 712 / SD 710 / SD 670, SD 835, SD 845 / SD 850, SDA660, SDM439, SDM630, SDM660, SDX20, SM7150, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-13887?
CVE-2018-13887 is classified as a critical vulnerability due to its potential impact on device functionality and security.
How do I fix CVE-2018-13887?
To address CVE-2018-13887, users should apply the latest firmware updates provided by Qualcomm or their device manufacturer.
Which devices are affected by CVE-2018-13887?
CVE-2018-13887 impacts various Qualcomm platforms including Snapdragon Auto, Compute, Consumer IOT, and Wearables.
What are the risks associated with CVE-2018-13887?
The risks include potential unauthorized access and execution of arbitrary code due to integer overflow caused by untrusted header fields.
Is there a workaround for CVE-2018-13887?
Currently, the recommended method to mitigate CVE-2018-13887 is to ensure that your device uses the updated firmware to patch the vulnerability.