In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing a SetParam command packet in the VR service, the extracted name_len and value_len values are not checked and could potentially cause a buffer overflow in subsequent calls to memcpy().
Project Subscriptions
| Vendors | Products |
|---|---|
|
Qualcomm
Subscribe
|
Msm8909w
Subscribe
Msm8909w Firmware
Subscribe
Sd 205
Subscribe
Sd 205 Firmware
Subscribe
Sd 210
Subscribe
Sd 210 Firmware
Subscribe
Sd 212
Subscribe
Sd 212 Firmware
Subscribe
Sd 430
Subscribe
Sd 430 Firmware
Subscribe
Sd 450
Subscribe
Sd 450 Firmware
Subscribe
Sd 625
Subscribe
Sd 625 Firmware
Subscribe
Sd 650
Subscribe
Sd 650 Firmware
Subscribe
Sd 652
Subscribe
Sd 652 Firmware
Subscribe
Sd 820
Subscribe
Sd 820 Firmware
Subscribe
Sd 835
Subscribe
Sd 835 Firmware
Subscribe
Sd 845
Subscribe
Sd 845 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-9262 | In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 835, SD 845, while processing a SetParam command packet in the VR service, the extracted name_len and value_len values are not checked and could potentially cause a buffer overflow in subsequent calls to memcpy(). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qualcomm
Published:
Updated: 2024-09-17T00:52:14.959Z
Reserved: 2018-02-05T00:00:00.000Z
Link: CVE-2017-18127
No data.
Status : Modified
Published: 2018-04-11T15:29:00.617
Modified: 2024-11-21T03:19:24.460
Link: CVE-2017-18127
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD