First published: Mon Aug 03 2020(Updated: )
u'Buffer overflow while parsing PMF enabled MCBC frames due to frame length being lesser than what is expected while parsing' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in IPQ6018, IPQ8074, Kamorta, Nicobar, QCA6390, QCA8081, QCN7605, QCS404, QCS405, QCS605, Rennell, SA415M, SC7180, SC8180X, SDA845, SDM670, SDM710, SDM845, SDM850, SM6150, SM7150, SM8150, SXR1130
Credit: product-security@qualcomm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Android | ||
Google Android | ||
Qualcomm Ipq6018 | ||
Qualcomm Ipq8074 Firmware | ||
Qualcomm Ipq8074 | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Nicobar | ||
Qualcomm Qca6390 Firmware | ||
Qualcomm Qca6390 | ||
Qualcomm Qca8081 Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Qcs404 Firmware | ||
Google Android | ||
Qualcomm Qcs405 Firmware | ||
Qualcomm Qcs405 | ||
Qualcomm Qcs605 Firmware | ||
Google Android | ||
Qualcomm Rennell Firmware | ||
Google Android | ||
Qualcomm Sa415m Firmware | ||
Google Android | ||
Google Android | ||
Google Android | ||
Qualcomm Sc8180x Firmware | ||
Qualcomm Sc8180x | ||
Qualcomm Sda845 Firmware | ||
Qualcomm Sda845 | ||
Qualcomm Sdm670 Firmware | ||
Qualcomm Sdm670 | ||
Qualcomm Sdm710 Firmware | ||
Qualcomm Sdm710 | ||
Qualcomm Sdm845 Firmware | ||
Qualcomm Sdm845 | ||
Qualcomm Sdm850 Firmware | ||
Qualcomm Sdm850 | ||
Qualcomm Sm6150 Firmware | ||
Qualcomm Sm6150 | ||
Qualcomm Sm7150 Firmware | ||
Qualcomm Sm7150 | ||
Qualcomm Sm8150 Firmware | ||
Qualcomm Sm8150 | ||
Qualcomm Sxr1130 Firmware | ||
Qualcomm Sxr1130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-3668 is a vulnerability that allows for a buffer overflow while parsing PMF enabled MCBC frames due to the frame length being lesser than what is expected while parsing.
The severity of CVE-2020-3668 is critical, with a severity score of 9.8.
The vulnerability affects Qualcomm Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, and Google Android.
To fix CVE-2020-3668, it is recommended to apply the necessary patches provided by Qualcomm and Google, as mentioned in the references.
The references for CVE-2020-3668 are: [link1], [link2], [link3]