CVE-2019-14067: Medium severity android vulnerability
Using non-time-constant functions like memcmp to compare sensitive data can lead to information leakage through timing side channel issue. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096, APQ8096AU, APQ8098, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9650, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, Nicobar, QCM2150, QCS404, QCS405, QCS605, QM215, Rennell, SA415M, SA6155P, SC7180, SC8180X, SDA660, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-14067?
CVE-2019-14067 has been classified as a medium severity vulnerability because it can lead to information leakage via timing side-channel attacks.
How do I fix CVE-2019-14067?
To mitigate CVE-2019-14067, ensure that comparisons of sensitive data use time-constant functions instead of memcmp.
What systems are affected by CVE-2019-14067?
CVE-2019-14067 affects various Qualcomm Snapdragon platforms, including automotive, consumer IoT, and mobile systems.
What kind of vulnerability is CVE-2019-14067?
CVE-2019-14067 is a timing side-channel vulnerability related to the improper comparison of sensitive data.
What is the impact of exploiting CVE-2019-14067?
Exploiting CVE-2019-14067 can lead to sensitive information leakage, potentially compromising user data security.