First published: Thu Apr 19 2018(Updated: )
The inputhub driver of HUAWEI P9 Lite mobile phones with Versions earlier than VNS-L21C02B341, Versions earlier than VNS-L21C22B380, Versions earlier than VNS-L31C02B341, Versions earlier than VNS-L31C440B390, Versions earlier than VNS-L31C636B396 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP and the APP may sends specific data to the inputhub driver to exploit this vulnerability, successful exploit could cause the system reboot.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P9 Lite Firmware | <vns-l31c02b341 | |
HUAWEI P9 Lite | ||
Huawei P9 Lite Firmware | <vns-l21c22b380 | |
Huawei P9 Lite Firmware | <vns-l31c440b390 | |
Huawei P9 Lite Firmware | <vns-l31c636b396 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-17313.
The severity of CVE-2017-17313 is high (5.5).
The affected software for CVE-2017-17313 is HUAWEI P9 Lite mobile phones with Versions earlier than VNS-L21C02B341, Versions earlier than VNS-L21C22B380, Versions earlier than VNS-L31C02B341, Versions earlier than VNS-L31C440B390, Versions earlier than VNS-L31C636B396.
The CWE ID for CVE-2017-17313 is 119.
To fix CVE-2017-17313, update the firmware of HUAWEI P9 Lite mobile phones to VNS-L21C02B341, VNS-L21C22B380, VNS-L31C02B341, VNS-L31C440B390, or VNS-L31C636B396.