PT-2018-6496 · Huawei · Huawei Mate 9 Pro
Pengfei Ding
+1
·
Published
2018-03-20
·
Updated
2018-04-13
·
CVE-2017-17320
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Huawei Mate 9 Pro smartphones with software of LON-AL00BC00B139D, LON-AL00BC00B229, LON-L29DC721B188
Description:
The issue is related to a memory double free vulnerability, where the system fails to manage memory properly, leading to the freeing of the same memory address twice. An attacker could trick a user with root privilege into installing a crafted application, potentially resulting in malicious code execution.
Recommendations:
For LON-AL00BC00B139D, update the software to a version that properly manages memory allocation to prevent double free vulnerabilities.
For LON-AL00BC00B229, apply a patch that corrects the memory management issue to prevent exploitation.
For LON-L29DC721B188, restrict the installation of crafted applications until a software update that fixes the memory double free issue is available.
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Mate 9 Pro