SB2019112104 - Code execution in Huawei Nova 5 and Nova 5i pro



SB2019112104 - Code execution in Huawei Nova 5 and Nova 5i pro

Published: November 21, 2019

Security Bulletin ID SB2019112104
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2019-5210)

The vulnerability allows a local attacker to execute arbitrary code on the target system.

The vulnerability exists due to the system does not properly validate the input value before use it as an array index when processing certain image information. A local attacker can trick a victim to install a malicious application and execute arbitrary code.


Remediation

Install update from vendor's website.