First published: Wed Nov 22 2017(Updated: )
Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause buffer overflow in the next system reboot, causing continuous system reboot or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <vtr-al00c00b123 | |
Huawei P10 | ||
Huawei P10 Plus Firmware | <vky-al00c00b123 | |
Huawei P10 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2017-2725.
The severity of CVE-2017-2725 is 7.8 (Critical).
Huawei P10 Plus and P10 smartphones with software versions earlier than VKY-AL00C00B123 and VTR-AL00C00B123 are affected by CVE-2017-2725.
An attacker with root privilege can trick a user into installing a malicious app, which can modify specific files and potentially exploit this buffer overflow vulnerability.
To fix CVE-2017-2725, upgrade the software of Huawei P10 Plus and P10 smartphones to VKY-AL00C00B123 and VTR-AL00C00B123 versions or later.