ZeroHour

CVE-2017-18294

CVSS 3.0
7.8 high
EPSS
<1%p18
Published
()
Modified
Description

While reading file class type from ELF header, a buffer overread may happen if the ELF file size is less than the size of ELF64 header size in Small Cell SoC, Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in version FSM9055, MDM9206, MDM9607, MDM9650, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 820, SD 820A, SD 835, SD 845, SDA660, SDX20.

Vendors
qualcomm
Products
fsm9055 firmware, mdm9206 firmware, mdm9607 firmware, mdm9650 firmware, msm8909w firmware, msm8996au firmware, sd 210 firmware, sd 212 firmware, sd 205 firmware, sd 425 firmware, sd 430 firmware, sd 450 firmware
Weakness
CWE-125
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.