CVE-2019-5282

Bastet module of some Huawei smartphones with Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12) have a double free vulnerability. An attacker tricks the user into installing a malicious application, which frees on the same memory address twice. Successful exploit could result in malicious code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:emily-al00a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-al00a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:emily-tl00b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-tl00b:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:emily-l09c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-l09c:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:emily-l29c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-l29c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:huawei:emily-l29c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-l29c:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:huawei:emily-l29c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-l29c:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:huawei:emily-l29c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:emily-l29c:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:huawei:hima-l09ca_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:hima-l09ca:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:huawei:hima-l29ca_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:hima-l29ca:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:huawei:hima-l29c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:huawei:hima-l29c:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:44

Type Values Removed Values Added
References () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190220-01-smartphone-en - Vendor Advisory () http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190220-01-smartphone-en - Vendor Advisory

Information

Published : 2019-11-13 14:15

Updated : 2024-11-21 04:44


NVD link : CVE-2019-5282

Mitre link : CVE-2019-5282

CVE.ORG link : CVE-2019-5282


JSON object : View

Products Affected

huawei

  • emily-l09c_firmware
  • hima-l29ca
  • emily-al00a_firmware
  • emily-l09c
  • hima-l09ca_firmware
  • emily-tl00b_firmware
  • hima-l29ca_firmware
  • emily-al00a
  • emily-l29c
  • emily-tl00b
  • hima-l29c_firmware
  • hima-l09ca
  • hima-l29c
  • emily-l29c_firmware
CWE
CWE-415

Double Free