HIGH · 7.5

CVE-2019-14012

Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking while processing SDP messages in Snapdragon Auto, Snapdragon Compute, Snapdragon ...

Vulnerability Description

Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking while processing SDP messages in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MSM8905, MSM8909, MSM8917, MSM8920, MSM8937, MSM8940, MSM8953, Nicobar, QCM2150, QM215, Rennell, SC7180, SC8180X, SDA845, SDM429, SDM439, SDM450, SDM632, SDM845, SDM850, SDX24, SM6150, SM7150, SM8150

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
QualcommMsm8905 Firmware-
QualcommMsm8905-
QualcommMsm8909 Firmware-
QualcommMsm8909-
QualcommMsm8917 Firmware-
QualcommMsm8917-
QualcommMsm8920 Firmware-
QualcommMsm8920-
QualcommMsm8937 Firmware-
QualcommMsm8937-
QualcommMsm8940 Firmware-
QualcommMsm8940-
QualcommMsm8953 Firmware-
QualcommMsm8953-
QualcommNicobar Firmware-
QualcommNicobar-
QualcommQcm2150 Firmware-
QualcommQcm2150-
QualcommQm215 Firmware-
QualcommQm215-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14012?

CVE-2019-14012 is a vulnerability with a CVSS score of 7.5 (HIGH). Possibility of null pointer deference as the array of video codecs from media info is referenced without null checking while processing SDP messages in Snapdragon Auto, Snapdragon Compute, Snapdragon ...

How severe is CVE-2019-14012?

CVE-2019-14012 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14012?

Check the references section above for vendor advisories and patch information. Affected products include: Qualcomm Msm8905 Firmware, Qualcomm Msm8905, Qualcomm Msm8909 Firmware, Qualcomm Msm8909, Qualcomm Msm8917 Firmware.