CVE-2020-3625

When making query to DSP capabilities, Stack out of bounds occurs due to wrong buffer length configured for DSP attributes in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Mobile in SM8250, SXR2130
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:qualcomm:sm8250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sm8250:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:qualcomm:sxr2130_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:sxr2130:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:31

Type Values Removed Values Added
References () https://www.qualcomm.com/company/product-security/bulletins/may-2020-bulletin - Vendor Advisory () https://www.qualcomm.com/company/product-security/bulletins/may-2020-bulletin - Vendor Advisory

Information

Published : 2020-06-02 15:15

Updated : 2024-11-21 05:31


NVD link : CVE-2020-3625

Mitre link : CVE-2020-3625

CVE.ORG link : CVE-2020-3625


JSON object : View

Products Affected

qualcomm

  • sm8250_firmware
  • sxr2130
  • sm8250
  • sxr2130_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')