CVE-2018-11877
Summary
| CVE | CVE-2018-11877 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-10-29 18:29:00 UTC |
| Updated | 2019-04-03 11:29:00 UTC |
| Description | When the buffer length passed is very large in WLAN, bounds check could be bypassed leading to potential buffer overwrite in Snapdragon Mobile in version SD 835, SD 845, SD 850, SDA660. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Qualcomm | Sda660 | - | All | All | All |
| Hardware | Qualcomm | Sda660 | - | All | All | All |
| Operating System | Qualcomm | Sda660 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sda660 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 835 | - | All | All | All |
| Hardware | Qualcomm | Sd 835 | - | All | All | All |
| Operating System | Qualcomm | Sd 835 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 835 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 845 | - | All | All | All |
| Hardware | Qualcomm | Sd 845 | - | All | All | All |
| Operating System | Qualcomm | Sd 845 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 845 Firmware | - | All | All | All |
| Hardware | Qualcomm | Sd 850 | - | All | All | All |
| Hardware | Qualcomm | Sd 850 | - | All | All | All |
| Operating System | Qualcomm | Sd 850 Firmware | - | All | All | All |
| Operating System | Qualcomm | Sd 850 Firmware | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Qualcomm Closed Source Components Multiple Unspecified Vulnerabilities | BID | www.securityfocus.com | |
| Bulletins | Qualcomm | CONFIRM | www.qualcomm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.