CVE-2017-2725

Severity
7.8HIGH
EPSS
0.2%
top 61.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 22
Latest updateMay 17

Description

Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overflow vulnerability. An attacker with the root privilege of an Android system may trick a user into installing a malicious APP. The APP can modify specific data to cause buffer overflow in the next system reboot, causing continuous system reboot or arbitrary code execution.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

â–¶NVDhuawei/p10_plus_firmware< vky-al00c00b123
â–¶NVDhuawei/p10_firmware< vtr-al00c00b123

🔴Vulnerability Details

2
GHSA
GHSA-52q5-gfc4-x6fx: Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overf↗2022-05-17
â–¶
CVEList
CVE-2017-2725: Bastet in P10 Plus and P10 smart phones with software earlier than VKY-AL00C00B123 versions, earlier than VTR-AL00C00B123 versions have a buffer overf↗2017-11-22
â–¶

💬Community

1
Bugzilla
CVE-2017-12944 libtiff: Mishandled memory allocation for short files in the TIFFReadDirEntryArray function↗2017-08-31
â–¶
CVE-2017-2725 (HIGH CVSS 7.8) | Bastet in P10 Plus and P10 smart ph | cvebase.io