First published: Fri Mar 09 2018(Updated: )
Touchscreen drive in Huawei H60 (Honor 6) Versions earlier than H60-L02_6.12.16 and P9 Plus Versions earlier than VIE-AL10BC00B356 has a stack overflow vulnerabilities. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter to touchscreen drive to crash the system or escalate privilege.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor 6 Firmware | <h60-l02_6.12.16 | |
Huawei Honor 6 | ||
Huawei P9 Plus Firmware | <vie-al10bc00b356 | |
Huawei P9 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2016-8783.
The severity of CVE-2016-8783 is critical, with a severity value of 7.8.
Versions earlier than H60-L02_6.12.16 of Huawei H60 (Honor 6) are affected by CVE-2016-8783.
Versions earlier than VIE-AL10BC00B356 of Huawei P9 Plus are affected by CVE-2016-8783.
An attacker can exploit CVE-2016-8783 by tricking a user into installing a malicious application on their smartphone and sending a given parameter to the touchscreen driver.