Double Free Vulnerability in Huawei Smartphones
CVE-2017-15330

5.5MEDIUM

Key Information:

Vendor
McAfee
Vendor
CVE Published:
15 February 2018

Summary

The Flp Driver in specific Huawei smartphones contains a double free vulnerability that can be exploited by malicious applications. Attackers can trick users into installing these applications, which have elevated privileges, allowing them to manipulate the device's memory management and potentially lead to a denial of service (DoS). This vulnerability highlights the importance of maintaining up-to-date software and being cautious with application installations.

Affected Version(s)

Vicky-AL00A Vicky-AL00AC00B124D, Vicky-AL00AC00B157D, Vicky-AL00AC00B167

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.