First published: Mon Oct 07 2019(Updated: )
Out of bound access due to lack of check of whiltelist array size while reading the image elf segments. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM845, SDM850, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130, SXR2130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Qualcomm 9205 Firmware | ||
Qualcomm 9205 | ||
qualcomm QCS404 firmware | ||
qualcomm QCS404 | ||
Qualcomm QCS605 firmware | ||
Qualcomm QCS605 | ||
qualcomm sda845 firmware | ||
qualcomm sda845 | ||
qualcomm sdm670 firmware | ||
qualcomm sdm670 | ||
qualcomm sdm710 firmware | ||
qualcomm sdm710 | ||
qualcomm SDM845 firmware | ||
qualcomm SDM845 | ||
qualcomm sdm850 firmware | ||
qualcomm sdm850 | ||
Qualcomm sdx24 firmware | ||
Qualcomm sdx24 | ||
Qualcomm sdx55 firmware | ||
Qualcomm sdx55 | ||
Qualcomm SM6150 | ||
Qualcomm SM6150 Firmware | ||
Qualcomm SM7150 Firmware | ||
qualcomm SM7150 firmware | ||
qualcomm SM8150 firmware | ||
qualcomm SM8150 | ||
Qualcomm SXR1130 Firmware | ||
Qualcomm SXR1130 | ||
qualcomm SXR2130 firmware | ||
qualcomm SXR2130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2339 is classified as a high-severity vulnerability due to its potential for unauthorized access and exploitation.
To fix CVE-2019-2339, ensure that your device firmware is updated to the latest version provided by your manufacturer.
CVE-2019-2339 affects various Qualcomm chipsets including those in the Snapdragon series, with particular vulnerability in devices utilizing MDM9205 and other mentioned firmware.
Yes, CVE-2019-2339 is a software vulnerability that arises from improper checks on image ELF segment processing.
Manufacturers, developers, and users of devices based on Qualcomm Snapdragon technology should be concerned about CVE-2019-2339 due to its security implications.