Vulnerability Name:

CVE-2015-9127 (CCN-143372)

Assigned:2017-08-16
Published:2018-04-05
Updated:2018-05-10
Summary:In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile and Snapdragon Wear MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 615/16/SD 415, and SD 810, possible null pointer dereference occurs due to failure of memory allocation when a large value is passed for buffer allocation in the Playready App.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.5 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.8 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: CCN
Type: Google Web site
Android

Source: MITRE
Type: CNA
CVE-2015-9127

Source: BID
Type: Third Party Advisory, VDB Entry
103671

Source: CCN
Type: BID-103671
Google Android Multiple Qualcomm Components Multiple Unspecified Security Vulnerabilities

Source: XF
Type: UNKNOWN
android-cve20159127-dos(143372)

Source: CCN
Type: Android Open Source Project
Android Security Bulletin—April 2018

Source: CONFIRM
Type: Vendor Advisory
https://source.android.com/security/bulletin/2018-04-01

Vulnerable Configuration:Configuration 1:
  • cpe:/o:qualcomm:msm8909w_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:msm8909w:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:qualcomm:sd_210_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_210:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:qualcomm:sd_212_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_212:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:qualcomm:sd_205_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_205:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:qualcomm:sd_400_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_400:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:qualcomm:sd_410_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_410:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:qualcomm:sd_412_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_412:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:qualcomm:sd_615_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_615:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:qualcomm:sd_616_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_616:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:qualcomm:sd_415_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_415:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:qualcomm:sd_810_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:qualcomm:sd_810:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:google:android:*:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    qualcomm msm8909w firmware -
    qualcomm msm8909w -
    qualcomm sd 210 firmware -
    qualcomm sd 210 -
    qualcomm sd 212 firmware -
    qualcomm sd 212 -
    qualcomm sd 205 firmware -
    qualcomm sd 205 -
    qualcomm sd 400 firmware -
    qualcomm sd 400 -
    qualcomm sd 410 firmware -
    qualcomm sd 410 -
    qualcomm sd 412 firmware -
    qualcomm sd 412 -
    qualcomm sd 615 firmware -
    qualcomm sd 615 -
    qualcomm sd 616 firmware -
    qualcomm sd 616 -
    qualcomm sd 415 firmware -
    qualcomm sd 415 -
    qualcomm sd 810 firmware -
    qualcomm sd 810 -
    google android *