First published: Wed Nov 22 2017(Updated: )
The boot loaders in Honor 5A smart phones with software Versions earlier than CAM-TL00C01B193,Versions earlier than CAM-TL00HC00B193,Versions earlier than CAM-UL00C00B193 have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause buffer overflow in the next system reboot, causing continuous system reboot or arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor 5a Firmware | <cam-tl00c01b193 | |
Huawei Honor 5a | ||
Huawei Honor 5a Firmware | <cam-tl00hc00b193 | |
Huawei Honor 5a Firmware | <cam-ul00c00b193 | |
Huawei P8 Lite Firmware | <ale-l02c635b568 | |
Huawei P8 Lite | ||
Huawei P8 Lite Firmware | <ale-l21c10b541 | |
Huawei P8 Lite Firmware | <ale-l21c185b568 | |
Huawei P8 Lite Firmware | <ale-l21c432b596 | |
Huawei P8 Lite Firmware | <ale-l21c464b595 | |
Huawei P8 Lite Firmware | <ale-l21c636b568 | |
Huawei P8 Lite Firmware | <ale-l23c605b535 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2729 is a vulnerability found in the boot loaders of Honor 5A smart phones with software versions earlier than CAM-TL00C01B193, CAM-TL00HC00B193, and CAM-UL00C00B193.
CVE-2017-2729 has a severity rating of 7.8 (Critical).
Huawei Honor 5A firmware versions earlier than CAM-TL00C01B193, CAM-TL00HC00B193, and CAM-UL00C00B193 are affected.
An attacker with root privilege of an Android system can trick a user into installing a malicious app to exploit the vulnerability.
No, other Huawei devices are not affected by CVE-2017-2729.