CVE-2019-14006: Input Validation
Buffer overflow occur while playing the clip which is nonstandard due to lack of offset length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14006?
CVE-2019-14006 is classified as a high severity vulnerability due to the potential for remote code execution through a buffer overflow.
How do I fix CVE-2019-14006?
To fix CVE-2019-14006, users should update their devices to the latest firmware provided by Qualcomm or Google.
Which devices are affected by CVE-2019-14006?
The devices affected by CVE-2019-14006 include those using various Qualcomm Snapdragon processors, including certain models from Snapdragon Auto, Mobile, and IoT series.
What type of vulnerability is CVE-2019-14006?
CVE-2019-14006 is a buffer overflow vulnerability that occurs during the playback of nonstandard media clips.
Can exploitation of CVE-2019-14006 lead to system compromise?
Yes, if successfully exploited, CVE-2019-14006 can allow an attacker to execute arbitrary code, potentially compromising the system.