ID

VAR-201810-0059


CVE

CVE-2017-18295


TITLE

plural Snapdragon Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2017-014303

DESCRIPTION

Possible buffer overflow if input is not null terminated in DSP Service module in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SDX20. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm MDM9206, etc. are the central processing unit (CPU) products of Qualcomm (Qualcomm) applied to different platforms. DSP Service module is one of the DSP (Digital Signal Processing) service modules. A buffer overflow vulnerability exists in DSP Services in several Qualcomm Snapdragon products. An attacker could exploit this vulnerability to cause a denial of service or execute code

Trust: 1.8

sources: NVD: CVE-2017-18295 // JVNDB: JVNDB-2017-014303 // VULHUB: VHN-109403 // VULMON: CVE-2017-18295

AFFECTED PRODUCTS

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdx20scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 415scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 450scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 615scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 616scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 625scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 652scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 820scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 820ascope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 835scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sdx20scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2017-014303 // CNNVD: CNNVD-201810-1156 // NVD: CVE-2017-18295

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-18295
value: HIGH

Trust: 1.0

NVD: CVE-2017-18295
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201810-1156
value: HIGH

Trust: 0.6

VULHUB: VHN-109403
value: HIGH

Trust: 0.1

VULMON: CVE-2017-18295
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2017-18295
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-109403
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-18295
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-109403 // VULMON: CVE-2017-18295 // JVNDB: JVNDB-2017-014303 // CNNVD: CNNVD-201810-1156 // NVD: CVE-2017-18295

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-109403 // JVNDB: JVNDB-2017-014303 // NVD: CVE-2017-18295

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201810-1156

TYPE

buffer overflow

Trust: 0.6

sources: CNNVD: CNNVD-201810-1156

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-014303

PATCH

title:October 2018 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Snapdragon product DSP Services Buffer error vulnerability fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=86254

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin—August 2018url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=746dc14fcd3f5e139648cfdc9d9039a9

Trust: 0.1

title:SamsungReleaseNotesurl:https://github.com/samreleasenotes/SamsungReleaseNotes

Trust: 0.1

sources: VULMON: CVE-2017-18295 // JVNDB: JVNDB-2017-014303 // CNNVD: CNNVD-201810-1156

EXTERNAL IDS

db:NVDid:CVE-2017-18295

Trust: 2.6

db:SECTRACKid:1041432

Trust: 1.2

db:JVNDBid:JVNDB-2017-014303

Trust: 0.8

db:CNNVDid:CNNVD-201810-1156

Trust: 0.7

db:VULHUBid:VHN-109403

Trust: 0.1

db:VULMONid:CVE-2017-18295

Trust: 0.1

sources: VULHUB: VHN-109403 // VULMON: CVE-2017-18295 // JVNDB: JVNDB-2017-014303 // CNNVD: CNNVD-201810-1156 // NVD: CVE-2017-18295

REFERENCES

url:https://source.android.com/security/bulletin/2018-08-01#qualcomm-closed-source-components

Trust: 1.8

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:http://www.securitytracker.com/id/1041432

Trust: 1.2

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-18295

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-18295

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/119.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://source.android.com/security/bulletin/2018-08-01.html

Trust: 0.1

url:https://github.com/samreleasenotes/samsungreleasenotes

Trust: 0.1

sources: VULHUB: VHN-109403 // VULMON: CVE-2017-18295 // JVNDB: JVNDB-2017-014303 // CNNVD: CNNVD-201810-1156 // NVD: CVE-2017-18295

SOURCES

db:VULHUBid:VHN-109403
db:VULMONid:CVE-2017-18295
db:JVNDBid:JVNDB-2017-014303
db:CNNVDid:CNNVD-201810-1156
db:NVDid:CVE-2017-18295

LAST UPDATE DATE

2024-11-23T21:02:36.375000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-109403date:2018-12-06T00:00:00
db:VULMONid:CVE-2017-18295date:2018-12-06T00:00:00
db:JVNDBid:JVNDB-2017-014303date:2019-01-11T00:00:00
db:CNNVDid:CNNVD-201810-1156date:2018-10-24T00:00:00
db:NVDid:CVE-2017-18295date:2024-11-21T03:19:47.733

SOURCES RELEASE DATE

db:VULHUBid:VHN-109403date:2018-10-23T00:00:00
db:VULMONid:CVE-2017-18295date:2018-10-23T00:00:00
db:JVNDBid:JVNDB-2017-014303date:2019-01-11T00:00:00
db:CNNVDid:CNNVD-201810-1156date:2018-10-24T00:00:00
db:NVDid:CVE-2017-18295date:2018-10-23T13:29:01.523