CVE-2018-11980
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
When a fake broadcast/multicast 11w rmf without mmie received, since no proper length check in wma_process_bip, buffer overflow will happen in both cds_is_mmie_valid and qdf_nbuf_trim_tail in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music in APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8937, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS605, SDM630, SDM636, SDM660, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130
Cuando se recibió una transmisión multidifusión falsa 11w rmf sin mmie, ya que no se comprobó la longitud apropiada en wma_process_bip, un desbordamiento del búfer se presentará en cds_is_mmie_valid y qdf_nbuf_trim_tail en los productos Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music en las versiones APQ8009, APQ8017, APQ8053, APQ8064, APQ8096AU, MDM9206, MDM9207C, MDM9607, MDM9640, MDM9650, MSM8937, MSM8996AU, MSM8998, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCN7605, QCS605, SDM630, SDM636, SDM660, SDX20, SDX24, SDX55, SM6150, SM7150, SM8150, SXR1130.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-06-07 CVE Reserved
- 2019-12-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.qualcomm.com/company/product-security/bulletins/december-2019-bulletin | 2019-12-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qualcomm Search vendor "Qualcomm" | Apq8009 Firmware Search vendor "Qualcomm" for product "Apq8009 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Apq8009 Search vendor "Qualcomm" for product "Apq8009" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Apq8017 Firmware Search vendor "Qualcomm" for product "Apq8017 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Apq8017 Search vendor "Qualcomm" for product "Apq8017" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Apq8053 Firmware Search vendor "Qualcomm" for product "Apq8053 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Apq8053 Search vendor "Qualcomm" for product "Apq8053" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Apq8064 Firmware Search vendor "Qualcomm" for product "Apq8064 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Apq8064 Search vendor "Qualcomm" for product "Apq8064" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Apq8096au Firmware Search vendor "Qualcomm" for product "Apq8096au Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Apq8096au Search vendor "Qualcomm" for product "Apq8096au" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9206 Firmware Search vendor "Qualcomm" for product "Mdm9206 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9206 Search vendor "Qualcomm" for product "Mdm9206" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9207c Firmware Search vendor "Qualcomm" for product "Mdm9207c Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9207c Search vendor "Qualcomm" for product "Mdm9207c" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9607 Firmware Search vendor "Qualcomm" for product "Mdm9607 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9607 Search vendor "Qualcomm" for product "Mdm9607" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9640 Firmware Search vendor "Qualcomm" for product "Mdm9640 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9640 Search vendor "Qualcomm" for product "Mdm9640" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Mdm9650 Firmware Search vendor "Qualcomm" for product "Mdm9650 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Mdm9650 Search vendor "Qualcomm" for product "Mdm9650" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Msm8937 Firmware Search vendor "Qualcomm" for product "Msm8937 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Msm8937 Search vendor "Qualcomm" for product "Msm8937" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Msm8996au Firmware Search vendor "Qualcomm" for product "Msm8996au Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Msm8996au Search vendor "Qualcomm" for product "Msm8996au" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Msm8998 Firmware Search vendor "Qualcomm" for product "Msm8998 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Msm8998 Search vendor "Qualcomm" for product "Msm8998" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6174a Firmware Search vendor "Qualcomm" for product "Qca6174a Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6174a Search vendor "Qualcomm" for product "Qca6174a" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca6574au Firmware Search vendor "Qualcomm" for product "Qca6574au Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca6574au Search vendor "Qualcomm" for product "Qca6574au" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca9377 Firmware Search vendor "Qualcomm" for product "Qca9377 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca9377 Search vendor "Qualcomm" for product "Qca9377" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qca9379 Firmware Search vendor "Qualcomm" for product "Qca9379 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qca9379 Search vendor "Qualcomm" for product "Qca9379" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcn7605 Firmware Search vendor "Qualcomm" for product "Qcn7605 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcn7605 Search vendor "Qualcomm" for product "Qcn7605" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Qcs605 Firmware Search vendor "Qualcomm" for product "Qcs605 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Qcs605 Search vendor "Qualcomm" for product "Qcs605" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdm630 Firmware Search vendor "Qualcomm" for product "Sdm630 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdm630 Search vendor "Qualcomm" for product "Sdm630" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdm636 Firmware Search vendor "Qualcomm" for product "Sdm636 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdm636 Search vendor "Qualcomm" for product "Sdm636" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdm660 Firmware Search vendor "Qualcomm" for product "Sdm660 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdm660 Search vendor "Qualcomm" for product "Sdm660" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdx20 Firmware Search vendor "Qualcomm" for product "Sdx20 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdx20 Search vendor "Qualcomm" for product "Sdx20" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdx24 Firmware Search vendor "Qualcomm" for product "Sdx24 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdx24 Search vendor "Qualcomm" for product "Sdx24" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sdx55 Firmware Search vendor "Qualcomm" for product "Sdx55 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sdx55 Search vendor "Qualcomm" for product "Sdx55" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sm6150 Firmware Search vendor "Qualcomm" for product "Sm6150 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sm6150 Search vendor "Qualcomm" for product "Sm6150" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sm7150 Firmware Search vendor "Qualcomm" for product "Sm7150 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sm7150 Search vendor "Qualcomm" for product "Sm7150" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sm8150 Firmware Search vendor "Qualcomm" for product "Sm8150 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sm8150 Search vendor "Qualcomm" for product "Sm8150" | - | - |
Safe
|
Qualcomm Search vendor "Qualcomm" | Sxr1130 Firmware Search vendor "Qualcomm" for product "Sxr1130 Firmware" | - | - |
Affected
| in | Qualcomm Search vendor "Qualcomm" | Sxr1130 Search vendor "Qualcomm" for product "Sxr1130" | - | - |
Safe
|