Vulnerability Description
The Flp Driver in some Huawei smartphones of the software Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167 has a double free vulnerability. An attacker can trick a user to install a malicious application which has a high privilege to exploit this vulnerability. Successful exploitation may cause denial of service (DoS) attack.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Vicky-Al00A Firmware | vicky-al00ac00b124d |
| Huawei | Vicky-Al00A | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-smartphVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171206-01-smartphVendor Advisory
FAQ
What is CVE-2017-15330?
CVE-2017-15330 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The Flp Driver in some Huawei smartphones of the software Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167 has a double free vulnerability. An attacker can trick a user to install a malici...
How severe is CVE-2017-15330?
CVE-2017-15330 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15330?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Vicky-Al00A Firmware, Huawei Vicky-Al00A.