PT-2018-5788 · Huawei · Prague

Bao Chenfu

+5

·

Published

2018-03-23

·

Updated

2018-04-19

·

CVE-2017-15325

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Prague smart phones versions earlier than Prague-AL00AC00B211 Prague smart phones versions earlier than Prague-AL00BC00B211 Prague smart phones versions earlier than Prague-AL00CC00B211 Prague smart phones versions earlier than Prague-TL00AC01B211 Prague smart phones versions earlier than Prague-TL10AC01B211
Description: The Bdat driver has an integer overflow issue due to a lack of parameter validation. This can be exploited by an attacker who tricks a user into installing a malicious APP, which can then send a specific parameter to the driver, potentially leading to arbitrary code execution.
Recommendations: For versions earlier than Prague-AL00AC00B211, update to Prague-AL00AC00B211 or later. For versions earlier than Prague-AL00BC00B211, update to Prague-AL00BC00B211 or later. For versions earlier than Prague-AL00CC00B211, update to Prague-AL00CC00B211 or later. For versions earlier than Prague-TL00AC01B211, update to Prague-TL00AC01B211 or later. For versions earlier than Prague-TL10AC01B211, update to Prague-TL10AC01B211 or later.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-15325

Affected Products

Prague