Vulnerability Description
Huawei Mate 9 Pro smartphones with software LON-AL00BC00B139D; LON-AL00BC00B229 have an integer overflow vulnerability. The camera driver does not validate the external input parameters and causes an integer overflow, which in the after processing results in a buffer overflow. An attacker tricks the user to install a crafted application, successful exploit could cause malicious code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Mate 9 Pro Firmware | lon-al00bc00b139d |
| Huawei | Mate 9 Pro | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180124-01-smVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/2018/huawei-sa-20180124-01-smVendor Advisory
FAQ
What is CVE-2017-17324?
CVE-2017-17324 is a vulnerability with a CVSS score of 7.8 (HIGH). Huawei Mate 9 Pro smartphones with software LON-AL00BC00B139D; LON-AL00BC00B229 have an integer overflow vulnerability. The camera driver does not validate the external input parameters and causes an ...
How severe is CVE-2017-17324?
CVE-2017-17324 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17324?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Mate 9 Pro Firmware, Huawei Mate 9 Pro.