CVE-2017-17773
Last modified
CVE-2017-17773 is a vulnerability of currently unknown severity. In Snapdragon Automobile, Snapdragon Wearable and Snapdragon Mobile MDM9206,MDM9607,MDM9650,SD 210/SD 212/SD 205,SD 400,SD 410/12,SD 425,SD 430,SD 450,SD 600,SD 602A,SD 615/16/SD 415,SD 617,SD 625,SD 650/52,SD 800,SD 808,SD 810,SD 820,SD 820Am,SD 835,SD 845,MSM8909W, improper input validation in video_fmt_mp4r_process_atom_avc1() causes a potential buffer overflow.. EPSS estimates a 1.49% chance of exploitation in the next 30 days.
Description
In Snapdragon Automobile, Snapdragon Wearable and Snapdragon Mobile MDM9206,MDM9607,MDM9650,SD 210/SD 212/SD 205,SD 400,SD 410/12,SD 425,SD 430,SD 450,SD 600,SD 602A,SD 615/16/SD 415,SD 617,SD 625,SD 650/52,SD 800,SD 808,SD 810,SD 820,SD 820Am,SD 835,SD 845,MSM8909W, improper input validation in video_fmt_mp4r_process_atom_avc1() causes a potential buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qualcomm | Mdm9206 Firmware | All versions |
| Qualcomm | Mdm9607 Firmware | All versions |
| Qualcomm | Mdm9650 Firmware | All versions |
| Qualcomm | Sd 210 Firmware | All versions |
| Qualcomm | Sd 212 Firmware | All versions |
| Qualcomm | Sd 412 Firmware | All versions |
| Qualcomm | Sd 410 Firmware | All versions |
| Qualcomm | Sd 425 Firmware | All versions |
| Qualcomm | Sd 430 Firmware | All versions |
| Qualcomm | Sd 616 Firmware | All versions |
| Qualcomm | Sd 615 Firmware | All versions |
| Qualcomm | Sd 415 Firmware | All versions |
| Qualcomm | Sd 617 Firmware | All versions |
| Qualcomm | Sd 625 Firmware | All versions |
| Qualcomm | Sd 650 Firmware | All versions |
| Qualcomm | Sd 652 Firmware | All versions |
| Qualcomm | Sd 820 Firmware | All versions |
| Qualcomm | S820am Firmware | All versions |
| Qualcomm | Sd 835 Firmware | All versions |
| Qualcomm | Sd 845 Firmware | All versions |
| Qualcomm | Sd 205 Firmware | All versions |
| Qualcomm | Sd 400 Firmware | All versions |
| Qualcomm | Sd 450 Firmware | All versions |
| Qualcomm | Sd 600 Firmware | All versions |
| Qualcomm | Sd 602a Firmware | All versions |
| Qualcomm | Sd 800 Firmware | All versions |
| Qualcomm | Sd 808 Firmware | All versions |
| Qualcomm | Sd 810 Firmware | All versions |
| Qualcomm | Msm8909w Firmware | All versions |
References
- http://www.securityfocus.com/bid/103292Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-03-01Third Party Advisory
- http://www.securityfocus.com/bid/103292Third Party Advisory, VDB Entry
- https://source.android.com/security/bulletin/2018-03-01Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-17773?
How severe is CVE-2017-17773?
How do I fix CVE-2017-17773?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-17766In wma_peer_info_event_handler() in Android for MSM, Firefox…
- CVE-2017-17767In all Qualcomm products with Android releases from CAF usin…
- CVE-2017-17769Information leakage in Android for MSM, Firefox OS for MSM, …
- CVE-2017-17770In Qualcomm Android for MSM, Firefox OS for MSM, and QRD And…
- CVE-2017-17771In msm_isp_prepare_v4l2_buf in Android for MSM, Firefox OS f…
- CVE-2017-17772In multiple functions that process 802.11 frames, out-of-bou…9.8
- CVE-2017-17774admin/configuration.php in Piwigo 2.9.2 has CSRF.
- CVE-2017-17775Piwigo 2.9.2 has XSS via the name parameter in an admin.php?…
- CVE-2017-17776Paid To Read Script 2.0.5 has full path disclosure via an in…
- CVE-2017-17777Paid To Read Script 2.0.5 has authentication bypass in the a…
- CVE-2017-17778Paid To Read Script 2.0.5 has XSS via the referrals.php tier…
- CVE-2017-17779Paid To Read Script 2.0.5 has SQL injection via the referral…
Are you affected by CVE-2017-17773?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
