Out-of-bounds read in Qualcomm products - CVE-2020-3688
Published: July 10, 2020 / Updated: March 3, 2021
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition in Video while parsing mp4 clip with corrupted sample atoms. A remote attacker can trigger out-of-bounds read error and read contents of memory on the system.
Affected software
MSM8937
MSM8920
MSM8917
SXR1130
SDM710
SDM670
SDA660
Rennell
SM7150
SM6150
SXR2130
SM8250
SM8150
MSM8940
SDM845
SDM660
SDM636
SDM632
SDM630
SDM450
SDM439
SDM429W
SDM429
SDA845
Saipan
SA6155P
MDM9207C
APQ8098
APQ8096AU
APQ8053
APQ8017
Kamorta
MSM8953
MSM8909W
MSM8905
MDM9607
APQ8009
MDM9206
MSM8996
MSM8996AU
MSM8998
QM215
QCS605
QCS405
QCM2150
QCA6574AU
Nicobar
Google Android