ID

VAR-201904-0544


CVE

CVE-2018-13918


TITLE

plural Snapdragon Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-015208

DESCRIPTION

kernel could return a received message length higher than expected, which leads to buffer overflow in a subsequent operation and stops normal operation in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, in MDM9150, MDM9206, MDM9607, MDM9650, MSM8909W, QCS605, Qualcomm 215, SD 425, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 675, SD 712 / SD 710 / SD 670, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDM439, SDX24, SM7150. plural Snapdragon The product contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm MDM9206 and others are products of Qualcomm (Qualcomm). MDM9206 is a central processing unit (CPU) product. SDX24 is a modem. SD 425 is a central processing unit (CPU) product. A buffer overflow vulnerability exists in the PMIC Modules of several Qualcomm products. The vulnerability is caused by the fact that the length of the received message returned by the kernel is longer than expected. An attacker could exploit this vulnerability to execute code or cause a denial of service

Trust: 1.8

sources: NVD: CVE-2018-13918 // JVNDB: JVNDB-2018-015208 // VULHUB: VHN-124025 // VULMON: CVE-2018-13918

AFFECTED PRODUCTS

vendor:qualcommmodel:sd 632scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdx24scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sm7150scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs605scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 710scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 675scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 429scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 850scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 845scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qm215scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9150scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 855scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 712scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9150scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:qcs605scope: - version: -

Trust: 0.8

vendor:qualcommmodel:215scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 425scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 429scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 439scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2018-015208 // NVD: CVE-2018-13918

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-13918
value: HIGH

Trust: 1.0

NVD: CVE-2018-13918
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201903-124
value: HIGH

Trust: 0.6

VULHUB: VHN-124025
value: HIGH

Trust: 0.1

VULMON: CVE-2018-13918
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-13918
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-124025
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-13918
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-124025 // VULMON: CVE-2018-13918 // JVNDB: JVNDB-2018-015208 // CNNVD: CNNVD-201903-124 // NVD: CVE-2018-13918

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-124025 // JVNDB: JVNDB-2018-015208 // NVD: CVE-2018-13918

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201903-124

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201903-124

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015208

PATCH

title:March 2019 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Product Buffer Error Vulnerability Fixurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89794

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin — March 2019url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=e9cddeba5732c8294d7cd6c4b6f1170b

Trust: 0.1

sources: VULMON: CVE-2018-13918 // JVNDB: JVNDB-2018-015208 // CNNVD: CNNVD-201903-124

EXTERNAL IDS

db:NVDid:CVE-2018-13918

Trust: 2.6

db:JVNDBid:JVNDB-2018-015208

Trust: 0.8

db:CNNVDid:CNNVD-201903-124

Trust: 0.7

db:VULHUBid:VHN-124025

Trust: 0.1

db:VULMONid:CVE-2018-13918

Trust: 0.1

sources: VULHUB: VHN-124025 // VULMON: CVE-2018-13918 // JVNDB: JVNDB-2018-015208 // CNNVD: CNNVD-201903-124 // NVD: CVE-2018-13918

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-13918

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-13918

Trust: 0.8

url:https://vigilance.fr/vulnerability/google-android-pixel-multiple-vulnerabilities-of-march-2019-28664

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/119.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

url:https://source.android.com/security/bulletin/2019-03-01.html

Trust: 0.1

sources: VULHUB: VHN-124025 // VULMON: CVE-2018-13918 // JVNDB: JVNDB-2018-015208 // CNNVD: CNNVD-201903-124 // NVD: CVE-2018-13918

SOURCES

db:VULHUBid:VHN-124025
db:VULMONid:CVE-2018-13918
db:JVNDBid:JVNDB-2018-015208
db:CNNVDid:CNNVD-201903-124
db:NVDid:CVE-2018-13918

LAST UPDATE DATE

2024-11-23T22:51:50.465000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-124025date:2019-05-29T00:00:00
db:VULMONid:CVE-2018-13918date:2019-05-29T00:00:00
db:JVNDBid:JVNDB-2018-015208date:2019-05-13T00:00:00
db:CNNVDid:CNNVD-201903-124date:2019-05-30T00:00:00
db:NVDid:CVE-2018-13918date:2024-11-21T03:48:20.217

SOURCES RELEASE DATE

db:VULHUBid:VHN-124025date:2019-04-04T00:00:00
db:VULMONid:CVE-2018-13918date:2019-04-04T00:00:00
db:JVNDBid:JVNDB-2018-015208date:2019-05-13T00:00:00
db:CNNVDid:CNNVD-201903-124date:2019-03-05T00:00:00
db:NVDid:CVE-2018-13918date:2019-04-04T15:29:00.923