Double Free Vulnerability in Huawei Smartphones
CVE-2019-5282

7.8HIGH

Key Information:

Vendor
Huawei
Vendor
CVE Published:
13 November 2019

Summary

The Bastet module in selected Huawei smartphones is susceptible to a double free vulnerability. An attacker may deceive users into installing a malicious application that can free the same memory address multiple times. This exploitation could lead to the execution of arbitrary malicious code, compromising device integrity and user data.

Affected Version(s)

Emily-AL00A, Emily-TL00B, Emily-L09C, Emily-L29C Versions earlier than Emily-AL00A 9.0.0.182(C00E82R1P21), Versions earlier than Emily-TL00B 9.0.0.182(C01E82R1P21), Versions earlier than Emily-L09C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.203(C432E7R1P11), Versions earlier than Emily-L29C 9.0.0.202(C185E2R1P12)

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.