In all Qualcomm products with Android releases from CAF using the Linux kernel, an array index out of bounds vulnerability exists in LPP.
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Link | Tags |
---|---|
https://source.android.com/security/bulletin/2017-07-01 | vendor advisory |
https://source.android.com/security/bulletin/2018-04-01 | |
http://www.securityfocus.com/bid/103671 | vdb entry |