MTK platform in Huawei smart phones with software of earlier than Nice-AL00C00B160 versions, earlier than Nice-AL10C00B140 versions has a out-of-bound read vulnerability. An attacker tricks a user into installing a malicious application on the smart phone, and send given parameter and cause to memory out-of-bound read.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20171115-01-mtk-en | vendor advisory |