CVE Database
/

CVE-2014-9995

Back to search

CVE-2014-9995

Published: Apr 18, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, in drmprov_cmd_verify_key(), the variable feature_name_length is not validated. There is a check for feature_name_len + filePathLen but there might be an integer wrap when checking feature_name_len + filePathLen. This leads to a buffer overflow.

VendorProductVersions

Qualcomm, Inc.

Snapdragon Mobile

affected
SD 400, SD 800

References

103671
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now