ZeroHour

CVE-2016-10411

CVSS 3.0
7.5 high
EPSS
<1%p57
Published
()
Modified
Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, SD 820, and SD 835, RTP daemon crashes and terminates VT call when UE receives RTCP unknown APP packet report which caused the parser to miss an end of RTCP packet length and go on forever looking for it, even going beyond the limits of the RTCP Packet length.

Vendors
qualcomm
Products
sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 400 firmware, sd 410 firmware, sd 412 firmware, sd 430 firmware, sd 450 firmware, sd 615 firmware, sd 616 firmware, sd 415 firmware, sd 617 firmware
Weakness
CWE-399
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.