CVE-2019-14003: Null Pointer Dereference
Null pointer exception can happen while parsing invalid MKV clip where cue information is parsed before segment information in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14003?
CVE-2019-14003 is classified as a high-severity vulnerability due to the potential for application crashes when processing invalid MKV files.
How do I fix CVE-2019-14003?
To mitigate CVE-2019-14003, update your Qualcomm firmware or Android device to the latest version that includes the security patch addressing this vulnerability.
Which devices are affected by CVE-2019-14003?
CVE-2019-14003 affects various devices utilizing Qualcomm's Snapdragon platforms, particularly those running specific firmware versions.
What causes the vulnerability CVE-2019-14003?
CVE-2019-14003 is caused by a null pointer exception that occurs during the parsing of invalid MKV clips when cue information is parsed before segment information.
Is CVE-2019-14003 being actively exploited?
As of now, there are no reports indicating that CVE-2019-14003 is being actively exploited in the wild.