In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.
References
Link | Resource |
---|---|
https://source.android.com/security/bulletin/2017-07-01 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99465 | Third Party Advisory VDB Entry |
Configurations
Information
Published : 2017-08-18 11:29
Updated : 2017-08-23 06:57
NVD link : CVE-2016-10389
Mitre link : CVE-2016-10389
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
- android