First published: Wed Nov 22 2017(Updated: )
The boot loaders of P10 and P10 Plus Huawei mobile phones with software the versions before Victoria-L09AC605B162, the versions before Victoria-L29AC605B162, the versions before Vicky-L29AC605B162 have an out-of-bounds memory access vulnerability due to the lack of parameter validation. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. the APP can modify specific data to cause buffer overflow in the next system reboot, causing out-of-bounds memory read which can continuous system reboot.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei P10 Firmware | <victoria-l09ac605b162 | |
Huawei P10 | ||
Huawei P10 Firmware | <victoria-l29ac605b162 | |
Huawei P10 Plus Firmware | <vicky-l29ac605b162 | |
Huawei P10 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8149 is an out-of-bounds memory access vulnerability in the boot loaders of P10 and P10 Plus Huawei mobile phones.
P10 and P10 Plus Huawei mobile phones with software versions before Victoria-L09AC605B162, Victoria-L29AC605B162, and Vicky-L29AC605B162 are affected by CVE-2017-8149.
CVE-2017-8149 has a severity rating of 5.5 (high).
The vulnerability in CVE-2017-8149 can be exploited by an attacker to trigger an out-of-bounds memory access and potentially execute arbitrary code.
Yes, Huawei has released software updates to address the vulnerability in CVE-2017-8149. It is recommended to update to software versions Victoria-L09AC605B162, Victoria-L29AC605B162, or Vicky-L29AC605B162 to fix the vulnerability.