First published: Mon Mar 05 2018(Updated: )
Huawei Mate 9 and Mate 9 pro smart phones with software the versions before MHA-AL00B 8.0.0.334(C00); the versions before LON-AL00B 8.0.0.334(C00) have a information leak vulnerability in the date service proxy implementation. An attacker may trick a user into installing a malicious application and application can exploit the vulnerability to get kernel date which may cause sensitive information leak.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 9 Pro Firmware | <lon-al00b_8.0.0.334\(c00\) | |
Huawei Mate 9 Pro | ||
Huawei Mate 9 Firmware | <mha-al00b_8.0.0.334\(c00\) | |
Huawei Mate 9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Huawei Mate 9 and Mate 9 Pro vulnerability is CVE-2017-17139.
The severity of CVE-2017-17139 is medium with a CVSS score of 5.5.
Huawei Mate 9 and Mate 9 Pro smart phones with software versions before MHA-AL00B 8.0.0.334(C00) and LON-AL00B 8.0.0.334(C00) are affected by this vulnerability.
This vulnerability allows an attacker to leak information through a malicious application, posing a risk to user privacy.
Yes, updating the software to version MHA-AL00B 8.0.0.334(C00) or LON-AL00B 8.0.0.334(C00) will fix this vulnerability.