ID

VAR-201907-0242


CVE

CVE-2019-2345


TITLE

plural Snapdragon Product race condition vulnerabilities

Trust: 0.8

sources: JVNDB: JVNDB-2019-007034

DESCRIPTION

Race condition while accessing DMA buffer in jpeg driver in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8909W, MSM8996AU, QCS605, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDM660, SDX20, SDX24. plural Snapdragon The product contains a race condition vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Qualcomm MSM8996AU and others are products of Qualcomm (Qualcomm). MSM8996AU is a central processing unit (CPU) product. SD 712 is a central processing unit (CPU) product. SDX24 is a modem. A race condition vulnerability exists in the Camera library in several Qualcomm products. The vulnerability stems from the improper handling of concurrent access when concurrent codes need to access shared resources mutually exclusive during the running of the network system or product

Trust: 1.71

sources: NVD: CVE-2019-2345 // JVNDB: JVNDB-2019-007034 // VULHUB: VHN-153780

AFFECTED PRODUCTS

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdx24scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs605scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 427scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 710scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 850scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 845scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdx20scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 435scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 712scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 636scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:qcs605scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 425scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 427scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 430scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 435scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 450scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 625scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 636scope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2019-007034 // NVD: CVE-2019-2345

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-2345
value: HIGH

Trust: 1.0

NVD: CVE-2019-2345
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201907-1336
value: HIGH

Trust: 0.6

VULHUB: VHN-153780
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2019-2345
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-153780
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-2345
baseSeverity: HIGH
baseScore: 7.0
vectorString: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.0
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-153780 // JVNDB: JVNDB-2019-007034 // CNNVD: CNNVD-201907-1336 // NVD: CVE-2019-2345

PROBLEMTYPE DATA

problemtype:CWE-362

Trust: 1.9

sources: VULHUB: VHN-153780 // JVNDB: JVNDB-2019-007034 // NVD: CVE-2019-2345

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201907-1336

TYPE

competition condition problem

Trust: 0.6

sources: CNNVD: CNNVD-201907-1336

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-007034

PATCH

title:July 2019 Code Aurora Security Bulletinurl:https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-security-bulletin

Trust: 0.8

title:Multiple Qualcomm product Camera Repair measures for vulnerabilities in library competition conditionsurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=95483

Trust: 0.6

sources: JVNDB: JVNDB-2019-007034 // CNNVD: CNNVD-201907-1336

EXTERNAL IDS

db:NVDid:CVE-2019-2345

Trust: 2.5

db:JVNDBid:JVNDB-2019-007034

Trust: 0.8

db:CNNVDid:CNNVD-201907-1336

Trust: 0.7

db:VULHUBid:VHN-153780

Trust: 0.1

sources: VULHUB: VHN-153780 // JVNDB: JVNDB-2019-007034 // CNNVD: CNNVD-201907-1336 // NVD: CVE-2019-2345

REFERENCES

url:https://www.codeaurora.org/security-bulletin/2019/07/01/july-2019-code-aurora-security-bulletin

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2019-2345

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-2345

Trust: 0.8

url:https://vigilance.fr/vulnerability/google-android-os-multiple-vulnerabilities-30243

Trust: 0.6

sources: VULHUB: VHN-153780 // JVNDB: JVNDB-2019-007034 // CNNVD: CNNVD-201907-1336 // NVD: CVE-2019-2345

SOURCES

db:VULHUBid:VHN-153780
db:JVNDBid:JVNDB-2019-007034
db:CNNVDid:CNNVD-201907-1336
db:NVDid:CVE-2019-2345

LAST UPDATE DATE

2024-11-23T22:44:57.412000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-153780date:2019-07-30T00:00:00
db:JVNDBid:JVNDB-2019-007034date:2019-07-31T00:00:00
db:CNNVDid:CNNVD-201907-1336date:2019-09-05T00:00:00
db:NVDid:CVE-2019-2345date:2024-11-21T04:40:45.537

SOURCES RELEASE DATE

db:VULHUBid:VHN-153780date:2019-07-25T00:00:00
db:JVNDBid:JVNDB-2019-007034date:2019-07-31T00:00:00
db:CNNVDid:CNNVD-201907-1336date:2019-07-25T00:00:00
db:NVDid:CVE-2019-2345date:2019-07-25T17:15:14.177