Double Free in Huawei Mate 10 - CVE-2019-5305

 

Double Free in Huawei Mate 10 - CVE-2019-5305

Published: January 30, 2019


Vulnerability identifier: #VU17272
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-5305
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The vulnerability exists due to a boundary error when handling malicious input. A remote attacker can trick the victim into installing the malicious application that can call special API, trigger double free error and cause the system crash.


Affected software

Huawei Mate 10

How to mitigate CVE-2019-5305

The vulnerability has been fixed in the version ALP-L29 9.0.0.159(C185).

Huawei Mate 10 - update to

External References

Related Security Bulletins