First published: Wed Nov 22 2017(Updated: )
The emerg_data driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions has a buffer overflow vulnerability. An attacker with the root privilege of the Android system can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone to crash the system or escalate privilege.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Y6ii Firmware | <=cam-l21c185b141 | |
Huawei Y6ii | ||
Huawei Y6ii Firmware | <=cam-l21c10b130 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2696 is a buffer overflow vulnerability in the emerg_data driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions.
CVE-2017-2696 affects Huawei Y6ii firmware versions up to and including cam-l21c10b130 and cam-l21c185b141.
CVE-2017-2696 has a severity rating of 7.8 (critical).
An attacker with root privileges can trick a user into installing a malicious application on the smartphone and send a given parameter to exploit the buffer overflow vulnerability.
Yes, Huawei has released a security advisory with information on how to mitigate the CVE-2017-2696 vulnerability.