This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy

Security Notice-Statement on Android KeyStore Stack Buffer Overflow Security Vulnerability

  • Initial Release Date: Jul 08, 2014
  • Last Release Date: Jul 08, 2014

Huawei was notified of Android KeyStore stack buffer overflow security vulnerability (CVE-2014-3100) released by NVD on July 2nd 2014. Huawei immediately launched a thorough investigation.

The investigation shows that none of Huawei Android smartphones or tablets is affected by the vulnerability.

This vulnerability exists in Android 4.3 and Google released a fix (ANDROID-10676015) in October 2013 to fix the vulnerability. After obtaining the fix, Huawei has fixed all smartphones and tablets running Android 4.3 before shipment. Therefore, none of Huawei smartphones or tablets sold in the market is affected by the vulnerability. 

2014-07-08 V1.0 FINAL

Huawei adheres to protecting the ultimate interests of users with best efforts and the principle of responsible disclosure and deal with product security issues through our response mechanism. Please report to Huawei PSIRT at psirt@huawei.com if you find any security vulnerability of Huawei products.