ID

VAR-201811-0555


CVE

CVE-2018-5918


TITLE

plural Snapdragon Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-012571

DESCRIPTION

Possible buffer overflow in DRM Trusted application due to lack of check function return values in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, SDA660, SDA845, SDX24, SXR1130. Snapdragon Automobile , Snapdragon Mobile , Snapdragon Wear Contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state

Trust: 1.71

sources: NVD: CVE-2018-5918 // JVNDB: JVNDB-2018-012571 // VULHUB: VHN-135950

AFFECTED PRODUCTS

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 810scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sda845scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sdx24scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 845scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sxr1130scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:sd 850scope:eqversion: -

Trust: 1.6

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 800scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 412scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 410scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 410scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 412scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-012571 // CNNVD: CNNVD-201811-842 // NVD: CVE-2018-5918

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-5918
value: HIGH

Trust: 1.0

NVD: CVE-2018-5918
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201811-842
value: MEDIUM

Trust: 0.6

VULHUB: VHN-135950
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-5918
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-135950
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-5918
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-135950 // JVNDB: JVNDB-2018-012571 // CNNVD: CNNVD-201811-842 // NVD: CVE-2018-5918

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-135950 // JVNDB: JVNDB-2018-012571 // NVD: CVE-2018-5918

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201811-842

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201811-842

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-012571

PATCH

title:November 2018 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Snapdragon Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=87066

Trust: 0.6

sources: JVNDB: JVNDB-2018-012571 // CNNVD: CNNVD-201811-842

EXTERNAL IDS

db:NVDid:CVE-2018-5918

Trust: 2.5

db:JVNDBid:JVNDB-2018-012571

Trust: 0.8

db:CNNVDid:CNNVD-201811-842

Trust: 0.6

db:VULHUBid:VHN-135950

Trust: 0.1

sources: VULHUB: VHN-135950 // JVNDB: JVNDB-2018-012571 // CNNVD: CNNVD-201811-842 // NVD: CVE-2018-5918

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.1

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-5918

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-5918

Trust: 0.8

url:https://vigilance.fr/vulnerability/google-android-pixel-multiple-vulnerabilities-of-november-2019-30795

Trust: 0.6

sources: VULHUB: VHN-135950 // JVNDB: JVNDB-2018-012571 // CNNVD: CNNVD-201811-842 // NVD: CVE-2018-5918

SOURCES

db:VULHUBid:VHN-135950
db:JVNDBid:JVNDB-2018-012571
db:CNNVDid:CNNVD-201811-842
db:NVDid:CVE-2018-5918

LAST UPDATE DATE

2024-11-23T22:48:32.214000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-135950date:2018-12-26T00:00:00
db:JVNDBid:JVNDB-2018-012571date:2019-02-05T00:00:00
db:CNNVDid:CNNVD-201811-842date:2019-11-07T00:00:00
db:NVDid:CVE-2018-5918date:2024-11-21T04:09:42.210

SOURCES RELEASE DATE

db:VULHUBid:VHN-135950date:2018-11-28T00:00:00
db:JVNDBid:JVNDB-2018-012571date:2019-02-05T00:00:00
db:CNNVDid:CNNVD-201811-842date:2018-11-29T00:00:00
db:NVDid:CVE-2018-5918date:2018-11-28T15:29:00.767