CVE-2019-14057: Critical severity Google Android vulnerability
Buffer Over read of codec private data while parsing an mkv file due to lack of check of buffer size before read in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, APQ8098, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8939, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCA6574AU, QCS405, QCS605, QM215, Rennell, SA6155P, Saipan, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14057?
CVE-2019-14057 has been assigned a severity rating that can range from medium to high, depending on the affected system configurations.
How do I fix CVE-2019-14057?
To fix CVE-2019-14057, apply the latest firmware updates provided by Qualcomm or relevant device manufacturers.
Which devices are affected by CVE-2019-14057?
CVE-2019-14057 affects various Qualcomm Snapdragon platforms including those used in automotive, connectivity, and consumer IoT devices.
Can CVE-2019-14057 lead to data leakage?
Yes, CVE-2019-14057 could potentially lead to data leakage due to buffer over-read vulnerabilities.
What types of systems are primarily impacted by CVE-2019-14057?
CVE-2019-14057 primarily impacts systems running on Qualcomm Snapdragon chipsets that handle MKV file parsing.