CVE-2017-8205: Integer Overflow
Published Nov 22, 2017
·Updated
The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has integer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has the root privilege; the APP can send a specific parameter to the driver of the smart phone, causing arbitrary code execution.
Affected Software
2 affected components
Huawei Honor 9 Firmware<stanford-al10c00b175
Huawei Honor 9
Event History
Nov 22, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2017-8205.
2
What is the severity rating of CVE-2017-8205?
CVE-2017-8205 has a severity rating of 7.8 (critical).
3
What is the affected software in CVE-2017-8205?
The affected software is Huawei Honor 9 with firmware versions earlier than Stanford-AL10C00B175.
4
How can an attacker exploit CVE-2017-8205?
An attacker can exploit CVE-2017-8205 by tricking a user into installing a malicious app with root privileges.
5
Are Huawei Honor 9 devices vulnerable to CVE-2017-8205?
No, Huawei Honor 9 devices are not vulnerable to CVE-2017-8205.