CVE-2017-17173

Due to insufficient parameters verification GPU driver of Mate 9 Pro Huawei smart phones with the versions before LON-AL00B 8.0.0.356(C00) has an arbitrary memory free vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to driver to release special kernel memory resource. Successful exploit may result in phone crash or arbitrary code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:mate_9_pro_fimware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:mate_9_pro:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:17

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180613-02-smartphone-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20180613-02-smartphone-en - Vendor Advisory

Information

Published : 2018-06-14 14:29

Updated : 2024-11-21 03:17


NVD link : CVE-2017-17173

Mitre link : CVE-2017-17173

CVE.ORG link : CVE-2017-17173


JSON object : View

Products Affected

huawei

  • mate_9_pro_fimware
  • mate_9_pro
CWE
CWE-20

Improper Input Validation