CVE-2017-2696: Buffer Overflow
The emergdata driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions has a buffer overflow vulnerability. An attacker with the root privilege of the Android system can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone to crash the system or escalate privilege.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-2696?
CVE-2017-2696 is a buffer overflow vulnerability in the emerg_data driver in CAM-L21C10B130 and earlier versions, CAM-L21C185B141 and earlier versions.
How does CVE-2017-2696 affect Huawei Y6ii firmware?
CVE-2017-2696 affects Huawei Y6ii firmware versions up to and including cam-l21c10b130 and cam-l21c185b141.
How severe is CVE-2017-2696?
CVE-2017-2696 has a severity rating of 7.8 (critical).
How can an attacker exploit the CVE-2017-2696 vulnerability?
An attacker with root privileges can trick a user into installing a malicious application on the smartphone and send a given parameter to exploit the buffer overflow vulnerability.
Is there a fix available for CVE-2017-2696?
Yes, Huawei has released a security advisory with information on how to mitigate the CVE-2017-2696 vulnerability.