First published: Tue Mar 20 2018(Updated: )
Huawei P9 smartphones with the versions before EVA-AL10C00B399SP02 have an information disclosure vulnerability. The software does not properly protect certain resource which can be accessed by multithreading. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could result in kernel information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P9 Firmware | <eva-al10c00b399sp02 | |
Huawei P9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17319 is an information disclosure vulnerability found in Huawei P9 smartphones with versions before EVA-AL10C00B399SP02.
CVE-2017-17319 has a severity rating of 5.5 (high).
CVE-2017-17319 allows an attacker to access certain resources on Huawei P9 smartphones by tricking a user with root privilege to install a crafted application.
Huawei P9 smartphones with versions before EVA-AL10C00B399SP02 are affected by CVE-2017-17319.
To fix CVE-2017-17319, upgrade your Huawei P9 smartphone to version EVA-AL10C00B399SP02 or higher.