There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en | Vendor Advisory |
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:49
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en - Vendor Advisory |
Information
Published : 2021-02-06 03:15
Updated : 2024-11-21 05:49
NVD link : CVE-2021-22304
Mitre link : CVE-2021-22304
CVE.ORG link : CVE-2021-22304
JSON object : View
Products Affected
huawei
- taurus-al00a_firmware
- taurus-al00a
CWE
CWE-416
Use After Free