CVE-2014-9995

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, in drmprov_cmd_verify_key(), the variable feature_name_length is not validated. There is a check for feature_name_len + filePathLen but there might be an integer wrap when checking feature_name_len + filePathLen. This leads to a buffer overflow.
References
Link Resource
http://www.securityfocus.com/bid/103671 Third Party Advisory VDB Entry
https://source.android.com/security/bulletin/2018-04-01 Vendor Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:sd_800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sd_800:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-04-18 14:29

Updated : 2023-12-10 12:30


NVD link : CVE-2014-9995

Mitre link : CVE-2014-9995

CVE.ORG link : CVE-2014-9995


JSON object : View

Products Affected

qualcomm

  • sd_400_firmware
  • sd_800
  • sd_800_firmware
  • sd_400
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer