First published: Wed Nov 22 2017(Updated: )
Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Agassi-l09hn Firmware | =ags-l09c233b019 | |
Huawei Agassi-l09hn | ||
Huawei Agassi-w09hn Firmware | =ags-w09c233b019 | |
Huawei Agassi-w09hn | ||
Huawei Kobe-l09ahn Firmware | =kob-l09c233b017 | |
Huawei Kobe-l09ahn | ||
Huawei Kobe-w09chn Firmware | =kob-w09c233b012 | |
Huawei Kobe-w09chn |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8159 is a type confusion vulnerability affecting some Huawei smartphones with specific software versions.
Huawei smartphones with software versions AGS-L09C233B019, AGS-W09C233B019, KOB-L09C233B017, and KOB-W09C233B012 are affected by CVE-2017-8159.
CVE-2017-8159 has a severity score of 7.8 (critical).
CVE-2017-8159 is a type confusion vulnerability where a variable is initialized using one type but later accessed using a different type, leading to potential security issues during certain operations.
To fix CVE-2017-8159, users should update their Huawei smartphones to the latest software versions provided by Huawei.