CVE-2020-3661: Buffer Overflow
Buffer overflow will happen while parsing mp4 clip with corrupted sample atoms values which exceeds MAXUINT32 range due to lack of validation checks in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Kamorta, MDM9206, MDM9207C, MDM9607, MSM8905, MSM8909W, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, MSM8996, MSM8996AU, MSM8998, QCA6574AU, QCS405, QCS605, QM215, Rennell, Saipan, SDA660, SDM429, SDM429W, SDM439, SDM450, SDM630, SDM632, SDM636, SDM660, SDM670, SDM710, SDM845, SDX20, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-3661?
CVE-2020-3661 is rated as a critical severity vulnerability due to the potential for remote code execution resulting from buffer overflow.
How do I fix CVE-2020-3661?
To fix CVE-2020-3661, update your device firmware to the latest version provided by Qualcomm or your device manufacturer.
Which devices are affected by CVE-2020-3661?
CVE-2020-3661 affects multiple Qualcomm Snapdragon products and firmware, including APQ8009, APQ8017, and others listed in the vulnerability report.
What type of vulnerability is CVE-2020-3661?
CVE-2020-3661 is a buffer overflow vulnerability caused by insufficient validation checks when parsing corrupted MP4 samples.
What are the potential impacts of CVE-2020-3661?
The potential impacts of CVE-2020-3661 include system crashes, unauthorized access, and execution of arbitrary code on vulnerable devices.