First published: Wed Nov 22 2017(Updated: )
Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Agassi-L09HN Firmware | =ags-l09c233b019 | |
Huawei Agassi-L09HN Firmware | ||
Huawei Agassi-W09HN Firmware | =ags-w09c233b019 | |
Huawei Agassi-W09HN Firmware | ||
Huawei Kobe-L09AHN | =kob-l09c233b017 | |
Huawei Kobe-L09AHN firmware | ||
Huawei Kobe-W09 | =kob-w09c233b012 | |
Huawei Kobe-W09 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8159 is a type confusion vulnerability affecting some Huawei smartphones with specific software versions.
Huawei smartphones with software versions AGS-L09C233B019, AGS-W09C233B019, KOB-L09C233B017, and KOB-W09C233B012 are affected by CVE-2017-8159.
CVE-2017-8159 has a severity score of 7.8 (critical).
CVE-2017-8159 is a type confusion vulnerability where a variable is initialized using one type but later accessed using a different type, leading to potential security issues during certain operations.
To fix CVE-2017-8159, users should update their Huawei smartphones to the latest software versions provided by Huawei.