This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy
HIFI driver of some Huawei products have a buffer overflow vulnerability due to the lack of a parameters check. An attacker may trick a user into installing a malicious application, and the application can send given parameter to HIFI driver to crash the system or escalate user privilege. (Vulnerability ID: HWPSIRT-2015-11009)
This vulnerability has been assigned Common Vulnerabilities and Exposures (CVE) ID: CVE-2015-8306.
Huawei has released software updates to fix these vulnerabilities. This advisory is available at the following link:
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20160104-03-smartphone-en
Product Name |
Affected Version |
Resolved Product and Version |
P8[1] |
GRA-TL00C01B220 and earlier versions |
GRA-TL00C01B230 |
GRA-CL00C92B220 and earlier versions |
GRA-CL00C92B230 |
|
GRA-CL10C92B220 and earlier versions |
GRA-CL10C92B230 |
|
GRA-UL00C00B220 and earlier versions |
GRA-UL00C00B230 |
|
GRA-UL10C00B220 and earlier versions |
GRA-UL10C00B230 |
|
Mate S[1] |
CRR-TL00C01B153SP01 and earlier versions |
CRR-TL00C01B160SP01 |
CRR-UL00C00B153 and earlier versions |
CRR-UL00C00B160 |
|
CRR-CL00C92B153 and earlier versions |
CRR-CL00C92B161 |
[1] Mobile phones will receive a system update prompt. The vulnerabilities will be fixed after users install the update.
The vulnerability classification has been performed by using the CVSSv2 scoring system (http://www.first.org/cvss/).
Base Score: 6.2 (AV:L/AC:H/Au:N/C:C/I:C/A:C)
Temporal Score: 5.1 (E:F/RL:O/RC:C)1. Prerequisite:
The attacker successfully tricks a user into installing a malicious application on the smart phone.
2. Attacking procedure:
HIFI driver of some Huawei products have a buffer overflow vulnerability due to the lack of a parameters check. An attacker may trick a user into installing a malicious application, and the application can send given parameter to HIFI driver to crash the system or escalate user privilege.
2016-02-03 V1.1 UPDATED updated information of "Software Versions and Fixes"
2016-01-04 V1.0 INITIAL
None