ID

VAR-201905-0756


CVE

CVE-2018-11953


TITLE

plural Snapdragon Product out-of-bounds vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-015503

DESCRIPTION

While processing ssid IE length from remote AP, possible out-of-bounds access may occur due to crafted ssid IE length in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, Qualcomm 215, SD 210/SD 212/SD 205, SD 425, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 650/52, SD 820, SD 820A, SDM439, SDX20. plural Snapdragon The product contains an out-of-bounds vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Google Android is prone to the following security vulnerabilities: 1. Multiple buffer-overflow vulnerabilities 2. Multiple information-disclosure vulnerabilities 3. Multiple security-bypass vulnerabilities 4. Multiple security vulnerabilities 5. Multiple integer overflow vulnerabilities An attacker can exploit these issues to bypass certain security restrictions and to perform unauthorized actions, gain elevated privileges, obtain sensitive information or execute arbitrary code. Failed exploits may result in a denial-of-service condition. These issues are being tracked by Android Bug IDs A-79377832, A-72957385, A-109741680, A-77527719, A-109741946, A-111127853, A-111128575, A-111126050, A-111125792, A-111128301, A-111128420, A-111128838, A-111128797, A-111128421, A-111128578, A-111127989, A-111128877, A-111128841, A-111126532, A-112277221, A-112276863, A-112278150, A-112277910, A-112277186, A-112278861, A-112277891, A-112278405, A-112277852, A-120487136*

Trust: 2.07

sources: NVD: CVE-2018-11953 // JVNDB: JVNDB-2018-015503 // BID: 107770 // VULHUB: VHN-121864 // VULMON: CVE-2018-11953

AFFECTED PRODUCTS

vendor:qualcommmodel:sd 632scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca9379scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 652scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 429scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca9377scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6574auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qca6174ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qm215scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9640scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9150scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdx20scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9150scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9640scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:qca6174ascope: - version: -

Trust: 0.8

vendor:qualcommmodel:qca6574auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:qca9377scope: - version: -

Trust: 0.8

vendor:googlemodel:androidscope:eqversion:0

Trust: 0.3

sources: BID: 107770 // JVNDB: JVNDB-2018-015503 // NVD: CVE-2018-11953

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-11953
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-11953
value: CRITICAL

Trust: 0.8

CNNVD: CNNVD-201904-079
value: CRITICAL

Trust: 0.6

VULHUB: VHN-121864
value: HIGH

Trust: 0.1

VULMON: CVE-2018-11953
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-11953
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-121864
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-11953
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-121864 // VULMON: CVE-2018-11953 // JVNDB: JVNDB-2018-015503 // CNNVD: CNNVD-201904-079 // NVD: CVE-2018-11953

PROBLEMTYPE DATA

problemtype:CWE-125

Trust: 1.9

sources: VULHUB: VHN-121864 // JVNDB: JVNDB-2018-015503 // NVD: CVE-2018-11953

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201904-079

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201904-079

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-015503

PATCH

title:April 2019 Code Aurora Security Bulletinurl:https://www.codeaurora.org/security-bulletin/2019/04/01/april-2019-code-aurora-security-bulletin

Trust: 0.8

title:Android WLAN HOST Fixes for component security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=91003

Trust: 0.6

title:Android Security Bulletins: Android Security Bulletin—April 2019url:https://vulmon.com/vendoradvisory?qidtp=android_security_bulletins&qid=cd95df8ce79ebdc8577685322caeeedf

Trust: 0.1

sources: VULMON: CVE-2018-11953 // JVNDB: JVNDB-2018-015503 // CNNVD: CNNVD-201904-079

EXTERNAL IDS

db:NVDid:CVE-2018-11953

Trust: 2.9

db:BIDid:107770

Trust: 1.0

db:JVNDBid:JVNDB-2018-015503

Trust: 0.8

db:CNNVDid:CNNVD-201904-079

Trust: 0.6

db:VULHUBid:VHN-121864

Trust: 0.1

db:VULMONid:CVE-2018-11953

Trust: 0.1

sources: VULHUB: VHN-121864 // VULMON: CVE-2018-11953 // BID: 107770 // JVNDB: JVNDB-2018-015503 // CNNVD: CNNVD-201904-079 // NVD: CVE-2018-11953

REFERENCES

url:https://www.codeaurora.org/security-bulletin/2019/04/01/april-2019-code-aurora-security-bulletin

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-11953

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-11953

Trust: 0.8

url:http://www.securityfocus.com/bid/107770

Trust: 0.7

url:https://vigilance.fr/vulnerability/google-android-pixel-multiple-vulnerabilities-of-april-2019-28925

Trust: 0.6

url:https://source.android.com/security/bulletin/2019-04-01.html

Trust: 0.4

url:http://code.google.com/android/

Trust: 0.3

url:https://cwe.mitre.org/data/definitions/125.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-121864 // VULMON: CVE-2018-11953 // BID: 107770 // JVNDB: JVNDB-2018-015503 // CNNVD: CNNVD-201904-079 // NVD: CVE-2018-11953

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 107770

SOURCES

db:VULHUBid:VHN-121864
db:VULMONid:CVE-2018-11953
db:BIDid:107770
db:JVNDBid:JVNDB-2018-015503
db:CNNVDid:CNNVD-201904-079
db:NVDid:CVE-2018-11953

LAST UPDATE DATE

2024-11-23T21:38:23.291000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-121864date:2019-05-29T00:00:00
db:VULMONid:CVE-2018-11953date:2019-05-29T00:00:00
db:BIDid:107770date:2019-04-01T00:00:00
db:JVNDBid:JVNDB-2018-015503date:2019-06-10T00:00:00
db:CNNVDid:CNNVD-201904-079date:2019-05-29T00:00:00
db:NVDid:CVE-2018-11953date:2024-11-21T03:44:19.180

SOURCES RELEASE DATE

db:VULHUBid:VHN-121864date:2019-05-24T00:00:00
db:VULMONid:CVE-2018-11953date:2019-05-24T00:00:00
db:BIDid:107770date:2019-04-01T00:00:00
db:JVNDBid:JVNDB-2018-015503date:2019-06-10T00:00:00
db:CNNVDid:CNNVD-201904-079date:2019-04-02T00:00:00
db:NVDid:CVE-2018-11953date:2019-05-24T17:29:01.570