In all Qualcomm products with Android releases from CAF using the Linux kernel, there is no size check for the images being flashed onto the NAND memory in their respective partitions, so there is a possibility of writing beyond the intended partition.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/99465 | Third Party Advisory VDB Entry |
https://source.android.com/security/bulletin/2017-07-01 | Patch Vendor Advisory |
http://www.securityfocus.com/bid/99465 | Third Party Advisory VDB Entry |
https://source.android.com/security/bulletin/2017-07-01 | Patch Vendor Advisory |
Configurations
History
21 Nov 2024, 02:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/99465 - Third Party Advisory, VDB Entry | |
References | () https://source.android.com/security/bulletin/2017-07-01 - Patch, Vendor Advisory |
Information
Published : 2017-08-18 18:29
Updated : 2024-11-21 02:43
NVD link : CVE-2016-10389
Mitre link : CVE-2016-10389
CVE.ORG link : CVE-2016-10389
JSON object : View
Products Affected
- android
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer