安全预警 - 涉及华为手机的DoS漏洞
- 预警编号:huawei-sa-20180530-01-smartphone
- 初始发布时间:2018-05-30
- 更新发布时间:2018-05-30
此漏洞的CVE编号为: CVE-2017-17171。
华为已发布版本修复该漏洞。安全预警链接:
http://www.huawei.com/cn/psirt/security-advisories/huawei-sa-20180530-01-smartphone-cn
产品名称 |
版本号 |
修复版本号 |
HUAWEI Mate 8 |
Versions earlier than NXT-AL10C00B592 |
NXT-AL10C00B593 |
Versions earlier than NXT-CL00C92B592 |
NXT-CL00C92B593 |
|
Versions earlier than NXT-DL00C17B592 |
NXT-DL00C17B593 |
|
Versions earlier than NXT-L09AC636B220 |
NXT-L09C636B598a |
|
Versions earlier than NXT-L09C185B582 |
NXT-L09C185B583 |
|
Versions earlier than NXT-L09C432B581 |
NXT-L09C432B582 |
|
Versions earlier than NXT-L09C605B585 |
NXT-L09C605B585CUSTC605D590 |
|
Versions earlier than NXT-L29C10B580 |
NXT-L29C10B583 |
|
Versions earlier than NXT-L29C185B582 |
NXT-L29C185B585 |
|
Versions earlier than NXT-L29C636B589 |
NXT-L29C636B594a |
|
Versions earlier than NXT-TL00C01B592 |
NXT-TL00C01B593 |
|
HUAWEI P9 |
Versions earlier than EVA-AL00C00B398 |
EVA-AL00C00B399SP02 |
Versions earlier than EVA-AL10C00B398 |
EVA-AL10C00B399SP02 |
|
Versions earlier than EVA-CL00C92B398 |
EVA-CL00C92B399SP02 |
|
Versions earlier than EVA-DL00C17B398 |
EVA-DL00C17B399SP02 |
|
Versions earlier than EVA-L09C185B391 |
EVA-L09C185B402 |
|
Versions earlier than EVA-L09C432B395 |
EVA-L09C432B501 |
|
Versions earlier than EVA-L09C464B383 |
EVA-L09C464B384 |
|
Versions earlier than EVA-L09C605B392 |
EVA-L09C605B393 |
|
Versions earlier than EVA-L09C635B391 |
EVA-L09C635B392 |
|
Versions earlier than EVA-L09C636B388 |
EVA-L09C636B390 |
|
Versions earlier than EVA-L19C10B394 |
EVA-L19C10B395 |
|
Versions earlier than EVA-L19C432B392 |
EVA-L19C432B396 |
|
Versions earlier than EVA-L19C605B390 |
EVA-L19C605B394 |
|
Versions earlier than EVA-L19C636B393 |
EVA-L19C636B394 |
|
Versions earlier than EVA-L29C636B389 |
EVA-L29C636B393 |
|
Versions earlier than EVA-TL00C01B398 |
EVA-TL00C01B399SP02 |
|
HUAWEI P9 Plus |
Versions earlier than VIE-L09C318B182 |
VIE-L09C318B190 |
Versions earlier than VIE-L09C432B380 |
VIE-L09C432B384 |
|
Versions earlier than VIE-L09C576B180 |
VIE-L09C576B332 |
|
Versions earlier than VIE-L29C605B370 |
VIE-L29C605B380 |
|
Versions earlier than VIE-L29C636B388 |
VIE-L29C636B391 |
基础得分:4.0 (AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:N/A:H)
临时得分:3.7 (E:F/RL:O/RC:C)
攻击者成功诱使用户安装一个恶意应用。
漏洞详细描述:
攻击者通过诱导用户安装恶意的APK,并通过特定权限预装应用发起攻击。应用程序可以利用该漏洞向手机驱动程序中发送特定参数,导致系统重启。
无
支持自动更新的手机会收到系统更新提示,手机用户通过执行系统更新,完成对漏洞的修复。
无
华为一贯主张尽全力保障产品用户的最终利益,遵循负责任的安全事件披露原则,并通过产品安全问题处理机制处理产品安全问题。
获取华为公司安全应急响应服务及华为产品漏洞信息,请访问http://www.huawei.com/cn/psirt。
反馈华为产品和解决方案安全问题,请反馈至华为PSIRT邮箱PSIRT@huawei.com,详情参考http://www.huawei.com/cn/psirt/report-vulnerabilities。