First published: Thu Jun 06 2019(Updated: )
There is a race condition vulnerability on Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C00E156R2P14T8), Honor 10 smartphones versions earlier than Columbia-AL10B 9.0.0.156(C00E156R1P20T8) and Honor Play smartphones versions earlier than Cornell-AL00A 9.0.0.156(C00E156R1P13T8). An attacker tricks the user into installing a malicious application, which makes multiple processes to operate the same variate at the same time. Successful exploit could cause execution of malicious code.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple High Sierra | <berkeley-al20_9.0.0.156\(c00e156r2p14t8\) | |
Apple High Sierra | ||
Huawei Honor 10 Firmware | <columbia-al10b_9.0.0.156\(c00e156r1p20t8\) | |
Huawei Honor 10 | ||
Huawei Honor Play Firmware | <cornell-al00a_9.0.0.156\(c00e156r1p13t8\) | |
Huawei Honor Play |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this race condition vulnerability is CVE-2019-5216.
The severity of CVE-2019-5216 is high with a severity value of 7.
Huawei Honor V10 smartphones versions earlier than Berkeley-AL20 9.0.0.156(C00E156R2P14T8), Honor 10 smartphones versions earlier than Columbia-AL10B 9.0.0.156(C00E156R1P20T8), and Honor Play smartphones versions earlier than Cornell-AL00A 9.0.0.156(C00E156R1P13T8) are affected by CVE-2019-5216.
To fix the race condition vulnerability on your Huawei smartphone, update to the latest firmware version mentioned in the security advisory released by Huawei.
You can find more information about CVE-2019-5216 in the security advisory released by Huawei, available at http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190116-01-smartphone-en.