First published: Mon Feb 25 2019(Updated: )
Lack of input validation for data received from user space can lead to an out of bound array issue in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 636, SD 820A, SD 835, SDM630, SDM660, SDX20.
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Qualcomm Snapdragon Auto Firmware | ||
Qualcomm Snapdragon Auto | ||
Qualcomm Snapdragon Consumer Internet Of Things Firmware | ||
Qualcomm Snapdragon Consumer Internet Of Things | ||
Qualcomm Snapdragon Industrial Internet Of Things Firmware | ||
Qualcomm Snapdragon Industrial Internet Of Things | ||
Qualcomm Mdm9150 Firmware | ||
Qualcomm Mdm9150 | ||
Qualcomm Mdm9206 Firmware | ||
Qualcomm Mdm9206 | ||
Qualcomm Mdm9607 Firmware | ||
Qualcomm Mdm9607 | ||
Qualcomm Mdm9650 Firmware | ||
Qualcomm Mdm9650 | ||
Qualcomm Msm8909w Firmware | ||
Qualcomm Msm8909w | ||
Qualcomm Msm8996au Firmware | ||
Qualcomm Msm8996au | ||
Qualcomm Sd 210 Firmware | ||
Qualcomm Sd 210 | ||
Qualcomm Sd 212 Firmware | ||
Qualcomm Sd 212 | ||
Qualcomm Sd 205 Firmware | ||
Qualcomm Sd 205 | ||
Qualcomm Sd 636 Firmware | ||
Qualcomm Sd 636 | ||
Qualcomm Sd 820a Firmware | ||
Qualcomm Sd 820a | ||
Qualcomm Sd 835 Firmware | ||
Qualcomm Sd 835 | ||
Qualcomm Sdm630 Firmware | ||
Qualcomm Sdm630 | ||
Qualcomm Sdm660 Firmware | ||
Qualcomm Sdm660 | ||
Qualcomm Sdx20 Firmware | ||
Qualcomm Sdx20 |
https://www.codeaurora.org/security-bulletin/2019/02/04/february-2019-code-aurora-security-bulletin
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13914 is a vulnerability that allows an attacker to cause an out-of-bound array issue in certain Qualcomm Snapdragon devices.
CVE-2018-13914 affects Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, and Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, and MSM8996AU, as well as SD 210, SD 212, and SD 205.
The severity of CVE-2018-13914 is high with a CVSS score of 7.8.
To fix CVE-2018-13914, it is recommended to apply the necessary security updates provided by Qualcomm.
You can find more information about CVE-2018-13914 in the February 2019 Code Aurora Security Bulletin issued by Qualcomm.