First published: Wed Nov 22 2017(Updated: )
The camera driver of MTK platform in Huawei smart phones with software of versions earlier than Nice-AL00C00B155 has a buffer overflow vulnerability.Due to the insufficient input verification, an attacker tricks a user into installing a malicious application which has special privilege and sends a specific parameter to the driver of the smart phone, causing privilege escalation.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mtk Platform Smart Phone Firmware | <nice-al00c00b155 | |
Huawei Mtk Platform Smart Phone |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8179 is considered a high severity vulnerability due to its potential to allow remote code execution via a buffer overflow.
To fix CVE-2017-8179, users should update their Huawei smartphones to the latest firmware version Nice-AL00C00B155 or later.
CVE-2017-8179 affects users of Huawei smartphones using the MTK platform with software versions earlier than Nice-AL00C00B155.
CVE-2017-8179 is exploited through malicious applications that trick users into installing software with special privileges.
Exploiting CVE-2017-8179 can lead to unauthorized access and control over the affected devices, posing serious security risks.