There is a use after free vulnerability in Taurus-AL00A 10.0.0.1(C00E1R1P1). A module may refer to some memory after it has been freed while dealing with some messages. Attackers can exploit this vulnerability by sending specific message to the affected module. This may lead to module crash, compromising normal service.
References
Link | Resource |
---|---|
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210127-03-smartphone-en | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: huawei
Published: 2021-02-06T02:18:09
Updated: 2021-02-06T02:18:09
Reserved: 2021-01-05T00:00:00
Link: CVE-2021-22304
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-02-06T03:15:12.890
Modified: 2021-02-10T22:55:48.897
Link: CVE-2021-22304
JSON object: View
Redhat Information
No data.
CWE