CVE-2018-5869: Input Validation
Published Dec 3, 2018
·Updated
Improper input validation in the QTEE keymaster app can lead to invalid memory access in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, SD 800, SD 810
Affected Software
27 affected components
Google Android
Qualcomm Mdm9206 Firmware
Qualcomm MDM9206
Qualcomm Mdm9607 Firmware
Qualcomm MDM9607
Qualcomm Msm8909w Firmware
Qualcomm MSM8909W
Qualcomm Sd 210 Firmware
Qualcomm SD 210
Qualcomm Sd 212 Firmware
Qualcomm SD 212
Qualcomm Sd 205 Firmware
Qualcomm SD 205
Qualcomm Sd 410 Firmware
Qualcomm SD 410
Qualcomm Sd 412 Firmware
Qualcomm Sd 412
Qualcomm Sd 615 Firmware
Qualcomm SD 615
Qualcomm Sd 616 Firmware
Qualcomm Sd 616
Qualcomm Sd 415 Firmware
Qualcomm SD 415
Qualcomm Sd 800 Firmware
Qualcomm SD 800
Qualcomm Sd 810 Firmware
Qualcomm SD 810
Event History
Dec 3, 2018
CVE Published
via Android·12:00 AM
Jan 18, 2019
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-5869.
2
How severe is CVE-2018-5869?
CVE-2018-5869 has a severity value of 7, which is considered high.
3
Which software versions are affected by CVE-2018-5869?
CVE-2018-5869 affects versions MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 615/16/SD 415, and SD 800, SD 810.
4
What is the impact of CVE-2018-5869?
CVE-2018-5869 can lead to invalid memory access in Snapdragon mobile and Snapdragon wear.
5
Where can I find more information about CVE-2018-5869?
You can find more information about CVE-2018-5869 on the Android Security Bulletin website and the SecurityFocus website.