First published: Fri Mar 09 2018(Updated: )
Huawei smartphones with software of MHA-AL00AC00B125 have an integer overflow vulnerability. The software does not process certain variable properly when handle certain process. An attacker tricks the user who has root privilege to install a crafted application, successful exploit could cause information disclosure.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mha-al00a Firmware | =mha-al00ac00b125 | |
Huawei Mha-al00a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17328 is considered to have a high severity due to the potential for integer overflow vulnerabilities that could allow an attacker to escalate privileges.
To fix CVE-2017-17328, ensure that your Huawei MHA-AL00A smartphone is updated to a version beyond MHA-AL00AC00B125.
CVE-2017-17328 affects users of Huawei smartphones running the MHA-AL00AC00B125 firmware.
An attacker can exploit CVE-2017-17328 by tricking a user with root privileges into installing a malicious application.
The risks associated with CVE-2017-17328 include unauthorized access and control of the affected device, leading to potential data breaches.