PT-2017-18159 · Google+1 · Android+2
Aravind Machiry
·
Published
2017-11-22
·
Updated
2017-12-08
·
CVE-2017-8150
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei P10 versions before Victoria-L09AC605B162
Huawei P10 versions before Victoria-L29AC605B162
Huawei P10 Plus versions before Vicky-L29AC605B162
Description
The issue is related to an arbitrary memory write vulnerability in the boot loaders of Huawei P10 and P10 Plus mobile phones. This vulnerability is caused by the lack of parameter validation. An attacker with root privilege of an Android system can trick a user into installing a malicious APP, which can modify specific data to cause arbitrary memory writing in the next system reboot. This can lead to continuous system reboot or arbitrary code execution.
Recommendations
For Huawei P10 versions before Victoria-L09AC605B162, update to a version after Victoria-L09AC605B162 to resolve the issue.
For Huawei P10 versions before Victoria-L29AC605B162, update to a version after Victoria-L29AC605B162 to resolve the issue.
For Huawei P10 Plus versions before Vicky-L29AC605B162, update to a version after Vicky-L29AC605B162 to resolve the issue.
As a temporary workaround, consider restricting the installation of APPs from untrusted sources to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Android
Huawei P10
Huawei P10 Plus