First published: Thu Jul 25 2019(Updated: )
Clients hostname gets added to DNS record on device which is running dnsmasq resulting in an information exposure in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables in MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 855, SDA660, SDM630, SDM660
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm MDM9206 | ||
Qualcomm MDM9206 firmware | ||
Qualcomm MD9607 Firmware | ||
Qualcomm MDM9607 firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9640 Firmware | ||
Qualcomm MDM9650 | ||
Qualcomm MDM9650 firmware | ||
Qualcomm 8909 Firmware | ||
Qualcomm Snapdragon 8909 | ||
qualcomm MSM8996AU firmware | ||
Qualcomm MSM8996AU Firmware | ||
Qualcomm QCS605 | ||
Qualcomm QCS605 Firmware | ||
Qualcomm SD210 Firmware | ||
Qualcomm SD 210 Firmware | ||
Qualcomm SD 212 | ||
Qualcomm SD 212 Firmware | ||
Qualcomm 205 Firmware | ||
Qualcomm SD205 Firmware | ||
Qualcomm SD615 Firmware | ||
Qualcomm Snapdragon 615 | ||
Qualcomm SD 616 Firmware | ||
Qualcomm Snapdragon 616 | ||
Qualcomm Snapdragon 415 Firmware | ||
Qualcomm Snapdragon 415 | ||
Qualcomm SD 625 Firmware | ||
Qualcomm Snapdragon 625 | ||
Qualcomm SDM636 Firmware | ||
Qualcomm Snapdragon 636 | ||
Qualcomm SD650 Firmware | ||
Qualcomm Snapdragon 650 | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD652 Firmware | ||
Qualcomm SD 675 Firmware | ||
Qualcomm Snapdragon 675 | ||
Qualcomm Snapdragon 712 Firmware | ||
Qualcomm Snapdragon 712 | ||
Qualcomm SD710 Firmware | ||
Qualcomm Snapdragon 710 | ||
Qualcomm SD 670 | ||
Qualcomm SDM670 | ||
Qualcomm SD 730 Firmware | ||
Qualcomm Snapdragon 730 | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820 Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD820A Firmware | ||
Qualcomm SD835 Firmware | ||
Qualcomm Snapdragon 835 | ||
Qualcomm SD855 Firmware | ||
Qualcomm SD855 Firmware | ||
Qualcomm SDA660 | ||
Qualcomm SDA660 | ||
Qualcomm SDM630 | ||
Qualcomm SDM630 Firmware | ||
Qualcomm SD660 Firmware | ||
Qualcomm Snapdragon 660 |
https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13897 is a vulnerability that allows clients' hostname to be added to a DNS record on a device running dnsmasq, resulting in an information exposure in various Qualcomm products.
Qualcomm Mdm9206 Firmware, Qualcomm Mdm9640 Firmware, Qualcomm Mdm9650 Firmware, Qualcomm Qcs605 Firmware, Qualcomm Sd 210 Firmware, Qualcomm Sd 212 Firmware, Qualcomm Sd 205 Firmware, Qualcomm Sd 616 Firmware, Qualcomm Sd 415 Firmware, Qualcomm Sd 625 Firmware, Qualcomm Sd 636 Firmware, Qualcomm Sd 712 Firmware, Qualcomm Sd 710 Firmware, Qualcomm Sd 670 Firmware, Qualcomm Sd 730 Firmware, Qualcomm Sd 820a Firmware, Qualcomm Sd 835 Firmware, Qualcomm Sd 855 Firmware, Qualcomm Sdm630 Firmware, Qualcomm Sdm660 Firmware.
The severity of CVE-2018-13897 is high with a CVSS score of 7.5.
CVE-2018-13897 allows an attacker to exploit the dnsmasq vulnerability and add clients' hostname to a DNS record, leading to an information exposure.
To fix CVE-2018-13897, users should update their devices with the latest firmware or software patches provided by Qualcomm.