PT-2017-18150 · Google+1 · Android+1
Yonggang Guo
·
Published
2017-11-22
·
Updated
2017-12-11
·
CVE-2017-8141
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
P10 Plus smart phones with software versions earlier than VKY-AL00C00B153
Description
The issue concerns a memory double free vulnerability in the Touch Panel driver. An attacker with root privilege of the Android system can trick a user into installing a malicious application. This application can start multiple threads and attempt to free specific memory, potentially triggering a double free condition. This could lead to a system crash or allow for arbitrary code execution.
Recommendations
For P10 Plus smart phones with software versions earlier than VKY-AL00C00B153, update to a version VKY-AL00C00B153 or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
P10 Plus