CVE-2017-17313

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
19/04/2018
Last modified:
22/05/2018

Description

The inputhub driver of HUAWEI P9 Lite mobile phones with Versions earlier than VNS-L21C02B341, Versions earlier than VNS-L21C22B380, Versions earlier than VNS-L31C02B341, Versions earlier than VNS-L31C440B390, Versions earlier than VNS-L31C636B396 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP and the APP may sends specific data to the inputhub driver to exploit this vulnerability, successful exploit could cause the system reboot.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* vns-l31c02b341 (excluding)
cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* vns-l21c22b380 (excluding)
cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* vns-l31c02b341 (excluding)
cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* vns-l31c440b390 (excluding)
cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:*
cpe:2.3:o:huawei:p9_lite_firmware:*:*:*:*:*:*:*:* vns-l31c636b396 (excluding)
cpe:2.3:h:huawei:p9_lite:-:*:*:*:*:*:*:*