9.8
CVSSv3

CVE-2015-9157

Published: 18/04/2018 Updated: 10/05/2018
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

In Android prior to 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9625, MDM9635M, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 600, SD 615/16/SD 415, SD 617, SD 650/52, SD 800, SD 808, and SD 810, in widevine_dash_cmd_handler(), rsp buffers are passed off to widevine commands. These rsp buffers have values in them, such as buffer lengths, that need to be validated to ensure that no buffer overflow/over-reads happen. However, rsp buffers are not always in locked memory, meaning a time-of-check, time-of-use issue can occur where we check that the value is valid, but then a race condition occurs where this memory is swapped out with a different, possibly out of range, value.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm mdm9206 firmware -

qualcomm mdm9607 firmware -

qualcomm ipq4019 firmware -

qualcomm mdm9625 firmware -

qualcomm mdm9635m firmware -

qualcomm msm8909w firmware -

qualcomm sd 210 firmware -

qualcomm sd 212 firmware -

qualcomm sd 205 firmware -

qualcomm sd 400 firmware -

qualcomm sd 410 firmware -

qualcomm sd 412 firmware -

qualcomm sd 600 firmware -

qualcomm sd 615 firmware -

qualcomm sd 616 firmware -

qualcomm sd 415 firmware -

qualcomm sd 617 firmware -

qualcomm sd 650 firmware -

qualcomm sd 652 firmware -

qualcomm sd 800 firmware -

qualcomm sd 808 firmware -

qualcomm sd 810 firmware -