PT-2017-18212 · Huawei · Huawei Smartphone
Dingbaozeng
+2
·
Published
2017-11-22
·
Updated
2017-12-06
·
CVE-2017-8208
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei smart phones versions earlier than NEM-AL10C00B356
Huawei smart phones versions earlier than Berlin-L21HNC432B360
Description
The issue is caused by a buffer overflow due to the lack of parameter validation in the driver. An attacker can trick a user into installing a malicious APP with root privilege, which can send a specific parameter to the driver, potentially causing a system reboot or arbitrary code execution.
Recommendations
For versions earlier than NEM-AL10C00B356, update to a version NEM-AL10C00B356 or later to resolve the issue.
For versions earlier than Berlin-L21HNC432B360, update to a version Berlin-L21HNC432B360 or later to resolve the issue.
As a temporary workaround, consider restricting the installation of APPs with root privilege to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Smartphone