PT-2019-17568 · Huawei · Huawei Mate 10
Published
2019-06-06
·
Updated
2019-06-10
·
CVE-2019-5305
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Huawei Mate 10 smartphones versions prior to ALP-L29 9.0.0.159(C185)
Description
The issue is related to a memory double free vulnerability in the image processing module. An attacker can exploit this by tricking a user into installing a malicious application, which can then call a special API to trigger the double free, potentially causing a system crash.
Recommendations
For versions prior to ALP-L29 9.0.0.159(C185), update to version ALP-L29 9.0.0.159(C185) or later to resolve the issue. As a temporary workaround, consider restricting the installation of applications from untrusted sources to minimize the risk of exploitation.
Fix
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Huawei Mate 10