ID

VAR-201809-0051


CVE

CVE-2017-18302


TITLE

Snapdragon Race condition vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-014292

DESCRIPTION

In Snapdragon (Automobile ,Mobile) in version MSM8996AU, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDA660, SDM429, SDM439, SDM630, SDM632, SDM636, SDM660, Snapdragon_High_Med_2016, a crafted HLOS client can modify the structure in memory passed to a QSEE application between the time of check and the time of use, resulting in arbitrary writes to TZ kernel memory regions. Snapdragon (Automobile and Mobile) Contains a race condition vulnerability.Information may be tampered with. Qualcomm MSM8996AU, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) for different platforms. A security vulnerability exists in Ontario_Driver_loctl in several Qualcomm Snapdragon products. An attacker can use a specially crafted HLOS client to exploit this vulnerability to change the frame in memory, thereby writing arbitrary content to the TZ kernel memory area. The following products (automotive and mobile) are affected: Qualcomm MSM8996AU; SD 425; SD 427; SD 430; SD 435; SD 450; SD 625; SD 650/52; SD 820; SD 820A; SD 835; SDM439; SDM630; SDM632; SDM636; SDM660; Snapdragon_High_Med_2016

Trust: 1.8

sources: NVD: CVE-2017-18302 // JVNDB: JVNDB-2017-014292 // VULHUB: VHN-109411 // VULMON: CVE-2017-18302

AFFECTED PRODUCTS

vendor:qualcommmodel:sdm439scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sdm636scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sdm660scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sdm632scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd820ascope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sdm429scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd835scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd820scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sdm630scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd435scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd427scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 425scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 427scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 430scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 435scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 450scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 625scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 652scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 820scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 820ascope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 835scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sda 660scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdm 429scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdm 439scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdm 630scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdm 632scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdm 636scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdm 660scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2017-014292 // CNNVD: CNNVD-201809-973 // NVD: CVE-2017-18302

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-18302
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-18302
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201809-973
value: MEDIUM

Trust: 0.6

VULHUB: VHN-109411
value: MEDIUM

Trust: 0.1

VULMON: CVE-2017-18302
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-18302
severity: MEDIUM
baseScore: 4.7
vectorString: AV:L/AC:M/AU:N/C:N/I:C/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-109411
severity: MEDIUM
baseScore: 4.7
vectorString: AV:L/AC:M/AU:N/C:N/I:C/A:N
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: COMPLETE
availabilityImpact: NONE
exploitabilityScore: 3.4
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-18302
baseSeverity: MEDIUM
baseScore: 4.7
vectorString: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: HIGH
availabilityImpact: NONE
exploitabilityScore: 1.0
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-109411 // VULMON: CVE-2017-18302 // JVNDB: JVNDB-2017-014292 // CNNVD: CNNVD-201809-973 // NVD: CVE-2017-18302

PROBLEMTYPE DATA

problemtype:CWE-362

Trust: 1.9

sources: VULHUB: VHN-109411 // JVNDB: JVNDB-2017-014292 // NVD: CVE-2017-18302

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201809-973

TYPE

competitive condition

Trust: 0.6

sources: CNNVD: CNNVD-201809-973

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014292

PATCH

title:Android のセキュリティに関する公開情報 - 2018 年 8 月url:https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components

Trust: 0.8

title:September 2018 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Snapdragon Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=85086

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin—August 2018url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=746dc14fcd3f5e139648cfdc9d9039a9

Trust: 0.1

title:SamsungReleaseNotesurl:https://github.com/samreleasenotes/SamsungReleaseNotes

Trust: 0.1

sources: VULMON: CVE-2017-18302 // JVNDB: JVNDB-2017-014292 // CNNVD: CNNVD-201809-973

EXTERNAL IDS

db:NVDid:CVE-2017-18302

Trust: 2.6

db:SECTRACKid:1041432

Trust: 1.2

db:JVNDBid:JVNDB-2017-014292

Trust: 0.8

db:CNNVDid:CNNVD-201809-973

Trust: 0.7

db:VULHUBid:VHN-109411

Trust: 0.1

db:VULMONid:CVE-2017-18302

Trust: 0.1

sources: VULHUB: VHN-109411 // VULMON: CVE-2017-18302 // JVNDB: JVNDB-2017-014292 // CNNVD: CNNVD-201809-973 // NVD: CVE-2017-18302

REFERENCES

url:https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components

Trust: 1.8

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:http://www.securitytracker.com/id/1041432

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-18302

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-18302

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/362.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://source.android.com/security/bulletin/2018-08-01.html

Trust: 0.1

url:https://github.com/samreleasenotes/samsungreleasenotes

Trust: 0.1

sources: VULHUB: VHN-109411 // VULMON: CVE-2017-18302 // JVNDB: JVNDB-2017-014292 // CNNVD: CNNVD-201809-973 // NVD: CVE-2017-18302

SOURCES

db:VULHUBid:VHN-109411
db:VULMONid:CVE-2017-18302
db:JVNDBid:JVNDB-2017-014292
db:CNNVDid:CNNVD-201809-973
db:NVDid:CVE-2017-18302

LAST UPDATE DATE

2024-11-23T20:11:37.755000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-109411date:2018-11-23T00:00:00
db:VULMONid:CVE-2017-18302date:2018-11-23T00:00:00
db:JVNDBid:JVNDB-2017-014292date:2018-12-25T00:00:00
db:CNNVDid:CNNVD-201809-973date:2018-09-21T00:00:00
db:NVDid:CVE-2017-18302date:2024-11-21T03:19:48.723

SOURCES RELEASE DATE

db:VULHUBid:VHN-109411date:2018-09-20T00:00:00
db:VULMONid:CVE-2017-18302date:2018-09-20T00:00:00
db:JVNDBid:JVNDB-2017-014292date:2018-12-25T00:00:00
db:CNNVDid:CNNVD-201809-973date:2018-09-21T00:00:00
db:NVDid:CVE-2017-18302date:2018-09-20T13:29:00.510