CVE-2019-14017: Buffer Overflow
Heap buffer overflow can occur while parsing invalid MKV clip which is not standard and have invalid vorbis codec data in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCS605, QM215, Rennell, SA6155P, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14017?
CVE-2019-14017 is categorized as critical due to its potential impact, enabling remote code execution on affected devices.
How do I fix CVE-2019-14017?
To fix CVE-2019-14017, apply the latest security patches provided by your device manufacturer or software provider.
Which products are affected by CVE-2019-14017?
CVE-2019-14017 affects various Qualcomm firmware products, including certain versions of Snapdragon and Android platforms.
Can CVE-2019-14017 be exploited remotely?
Yes, CVE-2019-14017 can be exploited remotely by sending specially crafted MKV files to vulnerable devices.
What are the symptoms of CVE-2019-14017 exploitation?
Symptoms of exploitation may include unexpected crashes, device instability, or unauthorized access to device functions.