CVE-2020-11140

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
21/01/2021
Last modified:
29/01/2021

Description

Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:qualcomm:apq8017:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8037:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8052:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8053:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8056:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8062:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8064au:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8076:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8084:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:apq8096au:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:aqt1000:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ar8031:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ar8035:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:ar8151:-:*:*:*:*:*:*:*
cpe:2.3:h:qualcomm:csra6620:-:*:*:*:*:*:*:*