CVE-2020-3679: Medium severity qualcomm bitra vulnerability
u'During execution after Address Space Layout Randomization is turned on for QTEE, part of code is still mapped at known address including code segments' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking in Bitra, Kamorta, Nicobar, QCS404, QCS610, Rennell, SA6155P, SA8155P, Saipan, SC7180, SC8180X, SDX55, SM6150, SM7150, SM8150, SM8250, SXR2130
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2020-3679.
What is the severity of CVE-2020-3679?
The severity of CVE-2020-3679 is medium with a severity value of 5.5.
Which software is affected by CVE-2020-3679?
The software affected by CVE-2020-3679 includes Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, and more.
How does CVE-2020-3679 impact the affected software?
CVE-2020-3679 allows part of the code to be still mapped at a known address, even after Address Space Layout Randomization (ASLR) is turned on for QTEE.
Is Qualcomm Bitra Firmware vulnerable to CVE-2020-3679?
Yes, Qualcomm Bitra Firmware is vulnerable to CVE-2020-3679.