Vulnerability Description
Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Huawei | Agassi-L09Hn Firmware | ags-l09c233b019 |
| Huawei | Agassi-L09Hn | - |
| Huawei | Agassi-W09Hn Firmware | ags-w09c233b019 |
| Huawei | Agassi-W09Hn | - |
| Huawei | Kobe-L09Ahn Firmware | kob-l09c233b017 |
| Huawei | Kobe-L09Ahn | - |
| Huawei | Kobe-W09Chn Firmware | kob-w09c233b012 |
| Huawei | Kobe-W09Chn | - |
Related Weaknesses (CWE)
References
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171018-02-smVendor Advisory
- http://www.huawei.com/en/psirt/security-advisories/2017/huawei-sa-20171018-02-smVendor Advisory
FAQ
What is CVE-2017-8159?
CVE-2017-8159 is a vulnerability with a CVSS score of 7.8 (HIGH). Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it lat...
How severe is CVE-2017-8159?
CVE-2017-8159 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8159?
Check the references section above for vendor advisories and patch information. Affected products include: Huawei Agassi-L09Hn Firmware, Huawei Agassi-L09Hn, Huawei Agassi-W09Hn Firmware, Huawei Agassi-W09Hn, Huawei Kobe-L09Ahn Firmware.