{"id": "CVE-2015-9208", "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 10.0, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C", "authentication": "NONE", "integrityImpact": "COMPLETE", "accessComplexity": "LOW", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": true, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "UNCHANGED", "version": "3.0", "baseScore": 9.8, "attackVector": "NETWORK", "baseSeverity": "CRITICAL", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 3.9}]}, "published": "2018-04-18T14:29:08.323", "references": [{"url": "http://www.securityfocus.com/bid/103671", "tags": ["Third Party Advisory", "VDB Entry"], "source": "product-security@qualcomm.com"}, {"url": "https://source.android.com/security/bulletin/2018-04-01", "tags": ["Vendor Advisory"], "source": "product-security@qualcomm.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-20"}]}], "descriptions": [{"lang": "en", "value": "In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800, and SD 810, the function tzbsp_pil_verify_sig() does not strictly check that the pointer to ELF and program headers and hash segment is within secure memory. It only checks that the address is not in non-secure memory. A given address range can overlap with both secure and non-secure regions - hence if such an address is passed in, it would not pass the non-secure range check, and would be considered valid by the function, even though that memory area could be modified by the non-secure side."}, {"lang": "es", "value": "En Android antes del nivel de parcheo de seguridad del 2018-04-05 o antes en Qualcomm Snapdragon Mobile y Snapdragon Wear IPQ4019, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, SD 800 y SD 810, la funci\u00f3n tzbsp_pil_verify_sig() no comprueba de forma estricta que el puntero a ELF y las cabeceras de programa y segmentos de hash se encuentren en la memoria segura. Solo comprueba que la direcci\u00f3n no est\u00e9 en la memoria no segura. Un rango de direcciones dado puede solaparse con regiones seguras y no seguras. Por lo tanto, si esa direcci\u00f3n se pasa, no pasar\u00eda la comprobaci\u00f3n de rango no seguro y se considerar\u00eda v\u00e1lida para la funci\u00f3n, incluso aunque ese \u00e1rea de memoria podr\u00eda ser modificada por el lado no seguro."}], "lastModified": "2018-05-09T14:32:09.637", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:mdm9206_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A960B86A-C397-4ACB-AEE6-55F316D32949"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:mdm9206:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D79B8959-3D1E-4B48-9181-D75FE90AAF98"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:mdm9607_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A35FECFB-60AE-42A8-BCBB-FEA7D5826D49"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:mdm9607:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "E9765187-8653-4D66-B230-B2CE862AC5C0"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:ipq4019_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "94CB547F-0078-47CD-B511-06DE96882D5A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:ipq4019:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "AA679375-BB14-4B24-8AD9-B2BFBACE2FDB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:mdm9635m_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9EF77DD1-BE11-4132-9889-646196FAE567"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:mdm9635m:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "CB323C15-2018-4CB8-858E-56F088B03FBB"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:mdm9640_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7FD1C359-C79B-4CE8-A192-5AA34D0BF05B"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:mdm9640:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "716B747E-672C-4B95-9D8E-1262338E67EA"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:mdm9645_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "65E5C59A-ABCF-4F62-8C6D-ECDACDAA83C9"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:mdm9645:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "1F8F856B-70D7-4A1A-8257-90AAAE62CD6F"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE28A59C-7AA6-4B85-84E8-07852B96108E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:msm8909w:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "5DEE828B-09A7-4AC1-8134-491A7C87C118"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0FA80D57-3191-47CF-AD3F-9F2D64E443FE"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_210:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "B2AFB212-F01A-4CEB-8DB4-2E0CC2308CB6"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0986EF1-0974-488E-84C4-6880F876CE55"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_212:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8C08BA58-2EBC-4A22-85A4-2ECD54693B9B"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "27110478-4C08-49E6-BD53-8BAAD9D5BD65"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_205:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3664D302-D22A-4B25-B534-3097AE2F8573"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AC3C20F8-9EFD-457C-B0B2-DA3C44A8B26D"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_400:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4B562043-7A0C-4692-A94F-EF4086BAA654"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_410_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F683C42D-A310-4369-9689-3DBC9288591E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_410:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "0EADE10A-0F63-4149-8F03-030673D6D7CE"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_412_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A78C9449-5EB0-459B-AA72-EFF00592C30A"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_412:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2D583172-F1F1-4DF8-99CE-B94A84D14CCD"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_615_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "549E6F7E-A54F-423F-BD4A-A8FB97DBD39E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_615:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "992C3835-7183-4D96-8647-DD9916880323"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_616_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A7B95CCC-37F1-4768-8D64-CA2028E93E03"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_616:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "D1426161-4F7C-44B1-AA9E-EA661AA68947"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_415_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ECF81213-DE2D-4C4B-99E8-71AFD87E92CD"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_415:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "95E826EF-343B-47FA-AB54-F13E868CE6A7"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_800_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "67E0DD11-0B28-4B6D-BDB7-0DBFA34A7187"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_800:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "551512D0-ED24-4B5A-BEB2-B090BB8DEE0C"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "95B4B4D4-0357-4E1D-9B72-635106D632CF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:qualcomm:sd_810:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "2F992088-5E31-4625-8C3B-CE7F946C61F2"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "product-security@qualcomm.com"}