ZeroHour

CVE-2020-11255

CVSS 3.1
7.5 high
EPSS
<1%p51
Published
()
Modified
Description

Denial of service while processing RTCP packets containing multiple SDES reports due to memory for last SDES packet is freed and rest of the memory is leaked in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Wearables

Vendors
qualcomm
Products
apq8009 firmware, apq8017 firmware, apq8037 firmware, apq8053 firmware, aqt1000 firmware, csrb31024 firmware, mdm8207 firmware, mdm9205 firmware, mdm9206 firmware, mdm9207 firmware, mdm9250 firmware, mdm9607 firmware
Weakness
CWE-401
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.