CVE-2017-8159

Some Huawei smartphones with software AGS-L09C233B019,AGS-W09C233B019,KOB-L09C233B017,KOB-W09C233B012 have a type confusion vulnerability. The program initializes a variable using one type, but it later accesses that variable using a type that is different with the original type when do certain register operation. Successful exploit could result in buffer overflow then may cause malicious code execution.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:huawei:agassi-l09hn_firmware:ags-l09c233b019:*:*:*:*:*:*:*
cpe:2.3:h:huawei:agassi-l09hn:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:huawei:agassi-w09hn_firmware:ags-w09c233b019:*:*:*:*:*:*:*
cpe:2.3:h:huawei:agassi-w09hn:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:huawei:kobe-l09ahn_firmware:kob-l09c233b017:*:*:*:*:*:*:*
cpe:2.3:h:huawei:kobe-l09ahn:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:huawei:kobe-w09chn_firmware:kob-w09c233b012:*:*:*:*:*:*:*
cpe:2.3:h:huawei:kobe-w09chn:-:*:*:*:*:*:*:*

Information

Published : 2017-11-22 11:29

Updated : 2017-12-12 09:40


NVD link : CVE-2017-8159

Mitre link : CVE-2017-8159


JSON object : View

CWE
CWE-704

Incorrect Type Conversion or Cast

Advertisement

dedicated server usa

Products Affected

huawei

  • kobe-w09chn
  • kobe-l09ahn_firmware
  • agassi-l09hn_firmware
  • agassi-l09hn
  • agassi-w09hn_firmware
  • agassi-w09hn
  • kobe-w09chn_firmware
  • kobe-l09ahn