PT-2016-3950 · Huawei · Huawei P8+1

Jianqiang Zhao

+2

·

Publicado

2016-04-07

·

Atualizado

2016-04-11

·

CVE-2015-8681

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Huawei P8 smartphones versions GRA-TL00 before GRA-TL00C01B230 Huawei P8 smartphones versions GRA-CL00 before GRA-CL00C92B230 Huawei P8 smartphones versions GRA-CL10 before GRA-CL10C92B230 Huawei P8 smartphones versions GRA-UL00 before GRA-UL00C00B230 Huawei P8 smartphones versions GRA-UL10 before GRA-UL10C00B230 Huawei Mate S smartphones versions CRR-TL00 before CRR-TL00C01B160SP01 Huawei Mate S smartphones versions CRR-UL00 before CRR-UL00C00B160 Huawei Mate S smartphones versions CRR-CL00 before CRR-CL00C92B161
Description The issue allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application with the camera permission. This is related to an interface access control issue in the ovisp driver.
Recommendations For Huawei P8 smartphones versions GRA-TL00 before GRA-TL00C01B230, update to version GRA-TL00C01B230 or later. For Huawei P8 smartphones versions GRA-CL00 before GRA-CL00C92B230, update to version GRA-CL00C92B230 or later. For Huawei P8 smartphones versions GRA-CL10 before GRA-CL10C92B230, update to version GRA-CL10C92B230 or later. For Huawei P8 smartphones versions GRA-UL00 before GRA-UL00C00B230, update to version GRA-UL00C00B230 or later. For Huawei P8 smartphones versions GRA-UL10 before GRA-UL10C00B230, update to version GRA-UL10C00B230 or later. For Huawei Mate S smartphones versions CRR-TL00 before CRR-TL00C01B160SP01, update to version CRR-TL00C01B160SP01 or later. For Huawei Mate S smartphones versions CRR-UL00 before CRR-UL00C00B160, update to version CRR-UL00C00B160 or later. For Huawei Mate S smartphones versions CRR-CL00 before CRR-CL00C92B161, update to version CRR-CL00C92B161 or later.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-8681

Produtos afetados

Huawei Mate S
Huawei P8