Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length check and eventually will lead to buffer overwrite when event data is copied to context buffer in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCA6574AU, QCN7605, QCS405, QCS605, SDM660, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130

Project Subscriptions

Vendors Products
Qualcomm Subscribe
Mdm9607 Subscribe
Mdm9607 Firmware Subscribe
Nicobar Subscribe
Nicobar Firmware Subscribe
Qca6574au Subscribe
Qca6574au Firmware Subscribe
Qcn7605 Subscribe
Qcn7605 Firmware Subscribe
Qcs405 Firmware Subscribe
Qcs605 Firmware Subscribe
Sdm660 Firmware Subscribe
Sdm845 Firmware Subscribe
Sdx55 Firmware Subscribe
Sm6150 Firmware Subscribe
Sm7150 Firmware Subscribe
Sm8150 Firmware Subscribe
Sm8250 Firmware Subscribe
Sxr1130 Subscribe
Sxr1130 Firmware Subscribe
Sxr2130 Subscribe
Sxr2130 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2341 Improper validation of event buffer extracted from FW response can lead to integer overflow, which will allow to pass the length check and eventually will lead to buffer overwrite when event data is copied to context buffer in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, Nicobar, QCA6574AU, QCN7605, QCS405, QCS605, SDM660, SDM845, SDX55, SM6150, SM7150, SM8150, SM8250, SXR1130, SXR2130
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: qualcomm

Published:

Updated: 2024-08-04T22:24:18.700Z

Reserved: 2019-03-29T00:00:00.000Z

Link: CVE-2019-10537

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-12-18T06:15:11.940

Modified: 2024-11-21T04:19:23.337

Link: CVE-2019-10537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses