First published: Wed Nov 22 2017(Updated: )
The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has integer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has the root privilege; the APP can send a specific parameter to the driver of the smart phone, causing arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Honor 9 Firmware | <stanford-al10c00b175 | |
Huawei Honor 9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-8205.
CVE-2017-8205 has a severity rating of 7.8 (critical).
The affected software is Huawei Honor 9 with firmware versions earlier than Stanford-AL10C00B175.
An attacker can exploit CVE-2017-8205 by tricking a user into installing a malicious app with root privileges.
No, Huawei Honor 9 devices are not vulnerable to CVE-2017-8205.