CVE-2019-2276
published 2019-07-25CVE-2019-2276: Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon…
critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — |
Android
CVE-2019-2276: WLAN HOST
vendor_android·2019-07-01·CVSS 9.8
CVE-2019-2276 [CRITICAL] CVE-2019-2276: WLAN HOST
Android Security Bulletin 2019-07-01
CVE: CVE-2019-2276
Severity: HIGH
Type: N/A
Component: WLAN HOST
References: A-130890737
QC-CR#2335974
GHSA
GHSA-269x-3w9j-5997: Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snap
ghsa_unreviewed·2022-05-24
CVE-2019-2276 [CRITICAL] CWE-125 GHSA-269x-3w9j-5997: Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snap
Possible out of bound read occurs while processing beaconing request due to lack of check on action frames received from user controlled space in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Mobile, Snapdragon Voice & Music in MDM9607, MSM8996AU, QCA6174A, QCA6574AU, QCA9377, QCA9379, QCS405, QCS605, SD 636, SD 665, SD 675, SD 712 / SD 710 / SD 670, SD 730, SD 820A, SD 845 / SD 850, SD 855, SDM630, SDM660, SDX24
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-13347 mercurial: Buffer underflow in mpatch.c:mpatch_apply()
bugzilla·2018-06-22·CVSS 7.5
CVE-2018-13347 [HIGH] CVE-2018-13347 mercurial: Buffer underflow in mpatch.c:mpatch_apply()
CVE-2018-13347 mercurial: Buffer underflow in mpatch.c:mpatch_apply()
Mercurial before version 4.6.1 is vulnerable to a buffer underflow in mpatch.c:mpatch_apply().
Upstream Changelog:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29
Upstream Patch:
https://www.mercurial-scm.org/repo/hg/rev/1acfc35d478c
Discussion:
Created mercurial tracking bugs for this issue:
Affects: fedora-all [bug 1594088]
---
This is related to CVE-2018-13346: this issue is writing before the output buffer, where the other reads past the end of input. In mercurial 2.6.2, it is present in the apply() function.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2276 https://access.redhat.com/errata/RHSA-2019:2276
---
This b
Bugzilla
CVE-2018-13346 mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply()
bugzilla·2018-06-22·CVSS 7.5
CVE-2018-13346 [HIGH] CVE-2018-13346 mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply()
CVE-2018-13346 mercurial: Missing check for fragment start position in mpatch.c:mpatch_apply()
Mercurial before version 4.6.1 has a missing check for fragment start position in mpatch.c:mpatch_apply()
Upstream Changelog:
https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29
Upstream Patch:
https://www.mercurial-scm.org/repo/hg/rev/faa924469635
Discussion:
This is related to CVE-2018-13347: this issue is reading past the end of input where the other writes before the output buffer. In mercurial 2.6.2, it is present in the apply() function.
---
Created mercurial tracking bugs for this issue:
Affects: fedora-all [bug 1594088]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2019:2276 https://access.redhat.co
2019-07-25
Published