First published: Thu Jun 06 2019(Updated: )
There is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0.0.167(C00E85R2P20T8). An attacker tricks the user into installing a malicious application, which make the software to reference memory after it has been freed. Successful exploit could cause a denial of service condition.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Mate 10 Firmware | <alp-al00b_9.0.0.167\(c00e85r2p20t8\) | |
Huawei Mate 10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-5214 is a use after free vulnerability on certain driver component in Huawei Mate10 smartphones versions earlier than ALP-AL00B 9.0.0.167(C00E85R2P20T8).
The severity of CVE-2019-5214 is rated as high with a severity value of 5.5.
CVE-2019-5214 allows an attacker to trick the user into installing a malicious application, which can cause the software to reference memory after it has been freed.
No, Huawei Mate 10 is not vulnerable to CVE-2019-5214.
To fix CVE-2019-5214, users of Huawei Mate10 smartphones should update their device to ALP-AL00B 9.0.0.167(C00E85R2P20T8) or later versions.