First published: Tue Jun 02 2020(Updated: )
Out of bound read in in fingerprint application due to requested data assigned to a local buffer without length check in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Kamorta, MDM9205, Nicobar, QCS404, QCS405, QCS605, Rennell, SA415M, SA6155P, SC7180, SC8180X, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
qualcomm Kamorta firmware | ||
qualcomm Kamorta | ||
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
qualcomm Nicobar firmware | ||
qualcomm Nicobar | ||
qualcomm QCS404 firmware | ||
qualcomm QCS404 | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS405 Firmware | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm Rennell firmware | ||
qualcomm Rennell | ||
Qualcomm sa415m firmware | ||
Qualcomm sa415m | ||
Qualcomm Sa6155p Firmware | ||
qualcomm SA6155P | ||
Qualcomm SC7180P Firmware | ||
Qualcomm SC7180P Firmware | ||
qualcomm SC8180X firmware | ||
qualcomm SC8180X | ||
qualcomm sdm670 firmware | ||
qualcomm sdm670 | ||
qualcomm sdm710 firmware | ||
qualcomm sdm710 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
qualcomm sdm850 firmware | ||
qualcomm sdm850 | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
qualcomm SM8250 firmware | ||
Qualcomm SM8250 | ||
Qualcomm SXR1130 Firmware | ||
Qualcomm SXR1130 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14042 is a vulnerability in the fingerprint application in Qualcomm devices.
Qualcomm devices with Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Inf are affected by CVE-2019-14042.
CVE-2019-14042 has a severity rating of 7.1 (High).
To fix CVE-2019-14042, it is recommended to install the security updates provided by Qualcomm. Please refer to the official Qualcomm website for more information.
For more information about CVE-2019-14042, you can visit the official Qualcomm website and refer to their May 2020 bulletin.