CVE-2017-17227
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
09/03/2018
Last modified:
26/03/2018
Description
GPU driver in Huawei Mate 10 smart phones with the versions before ALP-L09 8.0.0.120(C212); The versions before ALP-L09 8.0.0.127(C900); The versions before ALP-L09 8.0.0.128(402/C02/C109/C346/C432/C652) has a out-of-bounds memory access vulnerability due to the input parameters validation. An attacker tricks a user into installing a malicious application on the smart phone, and the application can call the driver with special parameter and cause accessing out-of-bounds memory. Successful exploit may result in phone crash or arbitrary code execution.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.120\(c212\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.127\(c900\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.128\(402\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.128\(c02\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.128\(c109\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.128\(c346\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.128\(c432\) (excluding) | |
| cpe:2.3:h:huawei:mate_10:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:huawei:mate_10_firmware:*:*:*:*:*:*:*:* | alp-l09_8.0.0.128\(c652\) (excluding) |
To consult the complete list of CPE names with products and versions, see this page



