CVE-2019-10594: Out-of-bounds Read
Stack overflow can occur when SDP is received with multiple payload types in the FMTP attribute of a video M line in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8076, APQ8096, APQ8096AU, APQ8098, MDM9150, MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS605, QM215, Rennell, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10594?
CVE-2019-10594 has been classified as a high severity vulnerability due to the potential for a stack overflow that can lead to system crashes or arbitrary code execution.
How do I fix CVE-2019-10594?
To mitigate CVE-2019-10594, users should update their affected hardware or firmware to the latest version provided by the manufacturer.
Which devices are affected by CVE-2019-10594?
CVE-2019-10594 affects various Qualcomm Snapdragon models, including Snapdragon Auto and Snapdragon Mobile, among others.
What is the impact of CVE-2019-10594?
The impact of CVE-2019-10594 can include system instability, crashes, and potential unauthorized access through exploitation.
Is CVE-2019-10594 remotely exploitable?
Yes, CVE-2019-10594 can potentially be exploited remotely if the vulnerable system is exposed to malicious payload variants.