CVE-2015-9138
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850, and SDX20, when an RSA encryption operation is called, the ce_util_to_unsigned_bin is invoked to convert the input buffer to unsigned binary. The ce_util_to_unsigned_bin function, instead of operating on the size of the unsigned character buffer that is passed, operates on the address - i.e. operates on "c" instead of "*c". Decrementing the address to check if it is less than zero means that the operation will always pass, since a pointer will never be less than zero, and may result in a buffer overflow.
En Android, antes del nivel de parche de seguridad del 2018-04-05 o antes en Qualcomm Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear y Small Cell SoC FSM9055, IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 600, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, SD 850 y SDX20, cuando se llama a una operación de cifrado RSA, ce_util_to_unsigned_bin se invoca para convertir el búfer de entrada en un binario sin firma. La función ce_util_to_unsigned_bin, en lugar de operar en el tamaño del búfer del carácter no firmado que se pasa, opera en la dirección; esto es, opera en "c" en lugar de en "*c". La disminución de la dirección para comprobar si es menor que cero significa que la operación pasará siempre, ya que un puntero nunca será menor que cero. Esto podría resultar en un desbordamiento de búfer.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-16 CVE Reserved
- 2018-04-18 CVE Published
- 2023-09-09 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103671 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://source.android.com/security/bulletin/2018-04-01 | 2018-05-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qualcomm Search vendor "Qualcomm" | Mdm9206 Firmware Search vendor "Qualcomm" for product "Mdm9206 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9206 Search vendor "Qualcomm" for product "Mdm9206" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9607 Firmware Search vendor "Qualcomm" for product "Mdm9607 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9607 Search vendor "Qualcomm" for product "Mdm9607" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Fsm9055 Firmware Search vendor "Qualcomm" for product "Fsm9055 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Fsm9055 Search vendor "Qualcomm" for product "Fsm9055" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9625 Firmware Search vendor "Qualcomm" for product "Mdm9625 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9625 Search vendor "Qualcomm" for product "Mdm9625" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9635m Firmware Search vendor "Qualcomm" for product "Mdm9635m Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9635m Search vendor "Qualcomm" for product "Mdm9635m" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9640 Firmware Search vendor "Qualcomm" for product "Mdm9640 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9640 Search vendor "Qualcomm" for product "Mdm9640" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9645 Firmware Search vendor "Qualcomm" for product "Mdm9645 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9645 Search vendor "Qualcomm" for product "Mdm9645" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9650 Firmware Search vendor "Qualcomm" for product "Mdm9650 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9650 Search vendor "Qualcomm" for product "Mdm9650" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9655 Firmware Search vendor "Qualcomm" for product "Mdm9655 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9655 Search vendor "Qualcomm" for product "Mdm9655" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Msm8909w Firmware Search vendor "Qualcomm" for product "Msm8909w Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Msm8909w Search vendor "Qualcomm" for product "Msm8909w" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 210 Firmware Search vendor "Qualcomm" for product "Sd 210 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 210 Search vendor "Qualcomm" for product "Sd 210" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 212 Firmware Search vendor "Qualcomm" for product "Sd 212 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 212 Search vendor "Qualcomm" for product "Sd 212" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 205 Firmware Search vendor "Qualcomm" for product "Sd 205 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 205 Search vendor "Qualcomm" for product "Sd 205" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 400 Firmware Search vendor "Qualcomm" for product "Sd 400 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 400 Search vendor "Qualcomm" for product "Sd 400" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 410 Firmware Search vendor "Qualcomm" for product "Sd 410 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 410 Search vendor "Qualcomm" for product "Sd 410" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 412 Firmware Search vendor "Qualcomm" for product "Sd 412 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 412 Search vendor "Qualcomm" for product "Sd 412" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 425 Firmware Search vendor "Qualcomm" for product "Sd 425 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 425 Search vendor "Qualcomm" for product "Sd 425" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 430 Firmware Search vendor "Qualcomm" for product "Sd 430 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 430 Search vendor "Qualcomm" for product "Sd 430" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 450 Firmware Search vendor "Qualcomm" for product "Sd 450 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 450 Search vendor "Qualcomm" for product "Sd 450" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 615 Firmware Search vendor "Qualcomm" for product "Sd 615 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 615 Search vendor "Qualcomm" for product "Sd 615" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 616 Firmware Search vendor "Qualcomm" for product "Sd 616 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 616 Search vendor "Qualcomm" for product "Sd 616" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 415 Firmware Search vendor "Qualcomm" for product "Sd 415 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 415 Search vendor "Qualcomm" for product "Sd 415" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 617 Firmware Search vendor "Qualcomm" for product "Sd 617 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 617 Search vendor "Qualcomm" for product "Sd 617" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 625 Firmware Search vendor "Qualcomm" for product "Sd 625 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 625 Search vendor "Qualcomm" for product "Sd 625" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 650 Firmware Search vendor "Qualcomm" for product "Sd 650 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 650 Search vendor "Qualcomm" for product "Sd 650" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 652 Firmware Search vendor "Qualcomm" for product "Sd 652 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 652 Search vendor "Qualcomm" for product "Sd 652" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 800 Firmware Search vendor "Qualcomm" for product "Sd 800 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 800 Search vendor "Qualcomm" for product "Sd 800" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 808 Firmware Search vendor "Qualcomm" for product "Sd 808 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 808 Search vendor "Qualcomm" for product "Sd 808" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 810 Firmware Search vendor "Qualcomm" for product "Sd 810 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 810 Search vendor "Qualcomm" for product "Sd 810" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 820 Firmware Search vendor "Qualcomm" for product "Sd 820 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 820 Search vendor "Qualcomm" for product "Sd 820" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 835 Firmware Search vendor "Qualcomm" for product "Sd 835 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 835 Search vendor "Qualcomm" for product "Sd 835" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 845 Firmware Search vendor "Qualcomm" for product "Sd 845 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 845 Search vendor "Qualcomm" for product "Sd 845" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdx20 Firmware Search vendor "Qualcomm" for product "Sdx20 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdx20 Search vendor "Qualcomm" for product "Sdx20" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 850 Firmware Search vendor "Qualcomm" for product "Sd 850 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 850 Search vendor "Qualcomm" for product "Sd 850" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Ipq4019 Firmware Search vendor "Qualcomm" for product "Ipq4019 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Ipq4019 Search vendor "Qualcomm" for product "Ipq4019" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 600 Firmware Search vendor "Qualcomm" for product "Sd 600 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 600 Search vendor "Qualcomm" for product "Sd 600" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sd 820a Firmware Search vendor "Qualcomm" for product "Sd 820a Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sd 820a Search vendor "Qualcomm" for product "Sd 820a" | - | - |
Safe
|