Security Advisory

CVE-2014-9995

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-04-18 14:00:00
Last updated 2024-09-16 22:51:02
Assigner qualcomm
CVSS score not scored
State PUBLISHED

Description

In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 400 and SD 800, in drmprov_cmd_verify_key(), the variable feature_name_length is not validated. There is a check for feature_name_len + filePathLen but there might be an integer wrap when checking feature_name_len + filePathLen. This leads to a buffer overflow.