Qualcomm Closed Source Components Multiple Security Vulnerabilities
BID:108300
Info
Qualcomm Closed Source Components Multiple Security Vulnerabilities
| Bugtraq ID: | 108300 |
| Class: | Unknown |
| CVE: |
CVE-2018-13898 CVE-2019-2255 CVE-2019-2256 CVE-2018-13901 CVE-2018-13902 CVE-2018-13906 CVE-2018-13907 CVE-2018-13908 CVE-2018-13909 CVE-2018-13910 CVE-2018-13911 CVE-2019-2257 CVE-2019-2259 |
| Remote: | Yes |
| Local: | No |
| Published: | May 06 2019 12:00AM |
| Updated: | May 06 2019 12:00AM |
| Credit: | derrek, Wen Guanxing of Pangu LAB, Xiling Gong of Tencent Blade Team. |
| Vulnerable: |
Google Pixel XL 0 Google Pixel C 0 Google Pixel 0 Google Nexus Player 0 Google Nexus 9 Google Nexus 6P Google Nexus 6 Google Nexus 5X Google Android 0 |
| Not Vulnerable: | |
Discussion
Qualcomm Closed Source Components Multiple Security Vulnerabilities
Qualcomm Closed-Source Components are prone to the following security vulnerabilities:
1. Multiple buffer-overflow vulnerabilities
2. Multiple information disclosure vulnerabilities
3. Multiple out-of-bounds memory access vulnerabilities
4. An unauthorized-access vulnerability
5. Multiple denial-of-service vulnerabilities
6. An insecure-file-permissions vulnerability
An attacker can exploit these issues to execute arbitrary code, perform unauthorized actions, cause denial-of-service condition and obtain sensitive information. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-114074547,A-119050181,A-122474428,A-114067283,A-119049466,A-119050073,A-119049388,A-119050001,A-119049623,A-119051002,A-119050182,A-119052037,A-122472140,A-112303441 and A-123997497.
Qualcomm Closed-Source Components are prone to the following security vulnerabilities:
1. Multiple buffer-overflow vulnerabilities
2. Multiple information disclosure vulnerabilities
3. Multiple out-of-bounds memory access vulnerabilities
4. An unauthorized-access vulnerability
5. Multiple denial-of-service vulnerabilities
6. An insecure-file-permissions vulnerability
An attacker can exploit these issues to execute arbitrary code, perform unauthorized actions, cause denial-of-service condition and obtain sensitive information. This may aid in further attacks.
These issues are being tracked by Android Bug IDs A-114074547,A-119050181,A-122474428,A-114067283,A-119049466,A-119050073,A-119049388,A-119050001,A-119049623,A-119051002,A-119050182,A-119052037,A-122472140,A-112303441 and A-123997497.
Exploit / POC
Qualcomm Closed Source Components Multiple Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].