CVE-2020-11196: Buffer Overflow
u'Integer overflow to buffer overflow occurs while playback of ASF clip having unexpected number of codec entries' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8009W, APQ8017, APQ8037, APQ8053, APQ8064AU, APQ8096, APQ8096AU, APQ8096SG, APQ8098, MDM9206, MDM9650, MSM8905, MSM8909, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8996SG, MSM8998, QCM4290, QCM6125, QCS405, QCS410, QCS4290, QCS603, QCS605, QCS610, QCS6125, QM215, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155, SA8155P, SA8195P, SDA429W, SDA640, SDA660, SDA670, SDA845, SDM429, SDM429W, SDM439, SDM450, SDM455, SDM630, SDM632, SDM636, SDM640, SDM660, SDM670, SDM710, SDM830, SDM845, SDW2500, SDX20, SDX20M, SDX50M, SDX55, SDX55M, SM4125, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6150, SM6150P, SM6250, SM6250P, SM6350, SM7125, SM7150, SM7150P, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SXR1120, SXR1130, SXR2130, SXR2130P, WCD9330
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-11196?
The severity of CVE-2020-11196 is classified as high due to potential exploitation leading to unauthorized access or information leakage.
How do I fix CVE-2020-11196?
To fix CVE-2020-11196, users should update their affected Qualcomm firmware or Android device to the latest security patch provided by their vendor.
Which devices are affected by CVE-2020-11196?
CVE-2020-11196 affects several Qualcomm Snapdragon products including APQ8009, APQ8017, and various models like Snapdragon Mobile and Snapdragon Wearables.
What type of vulnerability is CVE-2020-11196?
CVE-2020-11196 is an integer overflow vulnerability that can lead to buffer overflow during the playback of an ASF clip.
Is CVE-2020-11196 actively being exploited?
As of now, there is no public report indicating active exploitation of CVE-2020-11196, but it is recommended to apply the relevant patches to mitigate risks.