There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-02-05 19:15
Updated : 2021-02-10 14:55
NVD link : CVE-2021-22304
Mitre link : CVE-2021-22304
JSON object : View
CWE
CWE-416
Use After Free
Products Affected
huawei
- taurus-al00a_firmware
- taurus-al00a