Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth AVDTP/AVCTP messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-8451 Bluetooth module in some Huawei mobile phones with software LON-AL00BC00B229 and earlier versions has a buffer overflow vulnerability. Due to insufficient input validation, an unauthenticated attacker may craft Bluetooth AVDTP/AVCTP messages after successful paring, causing buffer overflow. Successful exploit may cause code execution.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: huawei

Published:

Updated: 2024-08-05T20:43:59.914Z

Reserved: 2017-12-04T00:00:00

Link: CVE-2017-17285

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-02-15T16:29:02.813

Modified: 2024-11-21T03:17:45.107

Link: CVE-2017-17285

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.