ID

VAR-201907-0559


CVE

CVE-2019-2243


TITLE

plural Snapdragon Product buffer error vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2019-006720

DESCRIPTION

Possible buffer overflow at the end of iterating loop while getting the version info and lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, QCS605, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820, SD 820A, SD 835, SD 845 / SD 850, SD 855, SDA660, SDM439, SDM630, SDM660. plural Snapdragon The product contains a buffer error vulnerability.Information may be obtained. Qualcomm Closed-Source Components are prone to multiple unspecified vulnerabilities. An attacker can exploit these issues to perform unauthorized actions. This may aid in further attacks. These issues are being tracked by Android Bug IDs A-120486477, A-120485121, A-120487163, A-122473494, and A-123998003. Qualcomm MDM9206 is a central processing unit (CPU) product of Qualcomm (Qualcomm). A buffer error vulnerability exists in the Debug Tools in several Qualcomm products

Trust: 2.07

sources: NVD: CVE-2019-2243 // JVNDB: JVNDB-2019-006720 // BID: 108546 // VULHUB: VHN-153678 // VULMON: CVE-2019-2243

AFFECTED PRODUCTS

vendor:qualcommmodel:sd 427scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sda660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 710scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 425scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 675scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 429scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820ascope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9607scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 730scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 615scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm660scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 450scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 616scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 435scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 665scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 712scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 625scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 632scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8996auscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 415scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:qcs605scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 205scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 212scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 835scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9650scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 850scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm630scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 845scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 820scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sdm439scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:msm8909wscope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 670scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 855scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 430scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 210scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:sd 636scope:eqversion: -

Trust: 1.0

vendor:qualcommmodel:mdm9206scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9607scope: - version: -

Trust: 0.8

vendor:qualcommmodel:mdm9650scope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8909wscope: - version: -

Trust: 0.8

vendor:qualcommmodel:msm8996auscope: - version: -

Trust: 0.8

vendor:qualcommmodel:qcs605scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 205scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 210scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 212scope: - version: -

Trust: 0.8

vendor:qualcommmodel:sd 425scope: - version: -

Trust: 0.8

vendor:googlemodel:pixel xlscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixel cscope:eqversion:0

Trust: 0.3

vendor:googlemodel:pixelscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexus playerscope:eqversion:0

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:9

Trust: 0.3

vendor:googlemodel:nexus 6pscope: - version: -

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:6

Trust: 0.3

vendor:googlemodel:nexusscope:eqversion:5x

Trust: 0.3

vendor:googlemodel:androidscope:eqversion:0

Trust: 0.3

sources: BID: 108546 // JVNDB: JVNDB-2019-006720 // NVD: CVE-2019-2243

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2019-2243
value: MEDIUM

Trust: 1.0

NVD: CVE-2019-2243
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201906-077
value: MEDIUM

Trust: 0.6

VULHUB: VHN-153678
value: LOW

Trust: 0.1

VULMON: CVE-2019-2243
value: LOW

Trust: 0.1

nvd@nist.gov: CVE-2019-2243
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

VULHUB: VHN-153678
severity: LOW
baseScore: 2.1
vectorString: AV:L/AC:L/AU:N/C:P/I:N/A:N
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2019-2243
baseSeverity: MEDIUM
baseScore: 5.5
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 1.8
impactScore: 3.6
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-153678 // VULMON: CVE-2019-2243 // JVNDB: JVNDB-2019-006720 // CNNVD: CNNVD-201906-077 // NVD: CVE-2019-2243

PROBLEMTYPE DATA

problemtype:CWE-119

Trust: 1.9

sources: VULHUB: VHN-153678 // JVNDB: JVNDB-2019-006720 // NVD: CVE-2019-2243

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201906-077

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-201906-077

CONFIGURATIONS

sources: JVNDB: JVNDB-2019-006720

PATCH

title:June 2019 Qualcomm Technologies, Inc. Security Bulletinurl:https://www.qualcomm.com/company/product-security/bulletins

Trust: 0.8

title:Multiple Qualcomm Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=93166

Trust: 0.6

title:The Registerurl:https://www.theregister.co.uk/2019/06/05/android_june_patch/

Trust: 0.1

sources: VULMON: CVE-2019-2243 // JVNDB: JVNDB-2019-006720 // CNNVD: CNNVD-201906-077

EXTERNAL IDS

db:NVDid:CVE-2019-2243

Trust: 2.9

db:BIDid:108546

Trust: 1.0

db:JVNDBid:JVNDB-2019-006720

Trust: 0.8

db:CNNVDid:CNNVD-201906-077

Trust: 0.7

db:VULHUBid:VHN-153678

Trust: 0.1

db:VULMONid:CVE-2019-2243

Trust: 0.1

sources: VULHUB: VHN-153678 // VULMON: CVE-2019-2243 // BID: 108546 // JVNDB: JVNDB-2019-006720 // CNNVD: CNNVD-201906-077 // NVD: CVE-2019-2243

REFERENCES

url:https://www.qualcomm.com/company/product-security/bulletins

Trust: 1.8

url:https://nvd.nist.gov/vuln/detail/cve-2019-2243

Trust: 1.4

url:http://code.google.com/android/

Trust: 0.9

url:http://www.qualcomm.com/

Trust: 0.9

url:https://source.android.com/security/bulletin/2019-06-01.html

Trust: 0.9

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2019-2243

Trust: 0.8

url:https://www.securityfocus.com/bid/108546

Trust: 0.7

url:https://vigilance.fr/vulnerability/google-android-multiple-vulnerabilities-of-june-2019-29461

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/119.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULHUB: VHN-153678 // VULMON: CVE-2019-2243 // BID: 108546 // JVNDB: JVNDB-2019-006720 // CNNVD: CNNVD-201906-077 // NVD: CVE-2019-2243

CREDITS

The vendor reported these issues.

Trust: 0.9

sources: BID: 108546 // CNNVD: CNNVD-201906-077

SOURCES

db:VULHUBid:VHN-153678
db:VULMONid:CVE-2019-2243
db:BIDid:108546
db:JVNDBid:JVNDB-2019-006720
db:CNNVDid:CNNVD-201906-077
db:NVDid:CVE-2019-2243

LAST UPDATE DATE

2024-11-23T21:52:06.807000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-153678date:2019-07-24T00:00:00
db:VULMONid:CVE-2019-2243date:2019-07-24T00:00:00
db:BIDid:108546date:2019-06-03T00:00:00
db:JVNDBid:JVNDB-2019-006720date:2019-07-25T00:00:00
db:CNNVDid:CNNVD-201906-077date:2019-07-25T00:00:00
db:NVDid:CVE-2019-2243date:2024-11-21T04:40:31.130

SOURCES RELEASE DATE

db:VULHUBid:VHN-153678date:2019-07-22T00:00:00
db:VULMONid:CVE-2019-2243date:2019-07-22T00:00:00
db:BIDid:108546date:2019-06-03T00:00:00
db:JVNDBid:JVNDB-2019-006720date:2019-07-25T00:00:00
db:CNNVDid:CNNVD-201906-077date:2019-06-03T00:00:00
db:NVDid:CVE-2019-2243date:2019-07-22T14:15:11.503