huawei alp-al00b_firmware 输入验证不恰当

admin 2023-12-01 21:55:28 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
huawei alp-al00b_firmware 输入验证不恰当

CVE编号

CVE-2019-5302

利用情况

暂无

补丁情况

N/A

披露时间

2020-04-28
漏洞描述
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1 out of 2 vulnerabilities. Different than CVE-2020-5303. Affected products are: ALP-AL00B: earlier than 9.1.0.333(C00E333R2P1T8) ALP-L09: earlier than 9.1.0.300(C432E4R1P9T8) ALP-L29: earlier than 9.1.0.315(C636E5R1P13T8) BLA-L29C: earlier than 9.1.0.321(C636E4R1P14T8), earlier than 9.1.0.330(C432E6R1P12T8), earlier than 9.1.0.302(C635E4R1P13T8) Berkeley-AL20: earlier than 9.1.0.333(C00E333R2P1T8) Berkeley-L09: earlier than 9.1.0.350(C10E3R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8), earlier than 9.1.0.350(C636E4R1P13T8) Charlotte-L09C: earlier than 9.1.0.311(C185E4R1P11T8), earlier than 9.1.0.345(C432E8R1P11T8) Charlotte-L29C: earlier than 9.1.0.325(C185E4R1P11T8), earlier than 9.1.0.335(C636E3R1P13T8), earlier than 9.1.0.345(C432E8R1P11T8), earlier than 9.1.0.336(C605E3R1P12T8) Columbia-AL10B: earlier than 9.1.0.333(C00E333R1P1T8) Columbia-L29D: earlier than 9.1.0.350(C461E3R1P11T8), earlier than 9.1.0.350(C185E3R1P12T8), earlier than 9.1.0.350(C10E5R1P14T8), earlier than 9.1.0.351(C432E5R1P13T8) Cornell-AL00A: earlier than 9.1.0.333(C00E333R1P1T8) Cornell-L29A: earlier than 9.1.0.328(C185E1R1P9T8), earlier than 9.1.0.328(C432E1R1P9T8), earlier than 9.1.0.330(C461E1R1P9T8), earlier than 9.1.0.328(C636E2R1P12T8) Emily-L09C: earlier than 9.1.0.336(C605E4R1P12T8), earlier than 9.1.0.311(C185E2R1P12T8), earlier than 9.1.0.345(C432E10R1P12T8) Emily-L29C: earlier than 9.1.0.311(C605E2R1P12T8), earlier than 9.1.0.311(C636E7R1P13T8), earlier than 9.1.0.311(C432E7R1P11T8) Ever-L29B: earlier than 9.1.0.311(C185E3R3P1), earlier than 9.1.0.310(C636E3R2P1), earlier than 9.1.0.310(C432E3R1P12) HUAWEI Mate 20: earlier than 9.1.0.131(C00E131R3P1) HUAWEI Mate 20 Pro: earlier than 9.1.0.310(C185E10R2P1) HUAWEI Mate 20 RS: earlier than 9.1.0.135(C786E133R3P1) HUAWEI Mate 20 X: earlier than 9.1.0.135(C00E133R2P1) HUAWEI P20: earlier than 9.1.0.333(C00E333R1P1T8) HUAWEI P20 Pro: earlier than 9.1.0.333(C00E333R1P1T8) HUAWEI P30: earlier than 9.1.0.193 HUAWEI P30 Pro: earlier than 9.1.0.186(C00E180R2P1) HUAWEI Y9 2019: earlier than 9.1.0.220(C605E3R1P1T8) HUAWEI nova lite 3: earlier than 9.1.0.305(C635E8R2P2) Honor 10 Lite: earlier than 9.1.0.283(C605E8R2P2) Honor 8X: earlier than 9.1.0.221(C461E2R1P1T8) Honor View 20: earlier than 9.1.0.238(C432E1R3P1) Jackman-L22: earlier than 9.1.0.247(C636E2R4P1T8) Paris-L21B: earlier than 9.1.0.331(C432E1R1P2T8) Paris-L21MEB: earlier than 9.1.0.331(C185E4R1P3T8) Paris-L29B: earlier than 9.1.0.331(C636E1R1P3T8) Sydney-AL00: earlier than 9.1.0.212(C00E62R1P7T8) Sydney-L21: earlier than 9.1.0.215(C432E1R1P1T8), earlier than 9.1.0.213(C185E1R1P1T8) Sydney-L21BR: earlier than 9.1.0.213(C185E1R1P2T8) Sydney-L22: earlier than 9.1.0.258(C636E1R1P1T8) Sydney-L22BR: earlier than 9.1.0.258(C636E1R1P1T8) SydneyM-AL00: earlier than 9.1.0.228(C00E78R1P7T8) SydneyM-L01: earlier than 9.1.0.215(C782E2R1P1T8), earlier than 9.1.0.213(C185E1R1P1T8), earlier than 9.1.0.270(C432E3R1P1T8) SydneyM-L03: earlier than 9.1.0.217(C605E1R1P1T8) SydneyM-L21: earlier than 9.1.0.221(C461E1R1P1T8), earlier than 9.1.0.215(C432E4R1P1T8) SydneyM-L22: earlier than 9.1.0.259(C185E1R1P2T8), earlier than 9.1.0.220(C635E1R1P2T8), earlier than 9.1.0.216(C569E1R1P1T8) SydneyM-L23: earlier than 9.1.0.226(C605E2R1P1T8) Yale-L21A: earlier than 9.1.0.154(C432E2R3P2), earlier than 9.1.0.154(C461E2R2P1), earlier than 9.1.0.154(C636E2R2P1) Honor 20: earlier than 9.1.0.152(C00E150R5P1) Honor Magic2: earlier than 10.0.0.187 Honor V20: earlier than 9.1.0.234(C00E234R4P3)
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20190814-01-mobile-en
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 huawei alp-al00b_firmware * Up to (excluding) 9.1.0.333\(c00e333r2p1t8\)
运行在以下环境
系统 huawei alp-l09_firmware * Up to (excluding) 9.1.0.300\(c432e4r1p9t8\)
运行在以下环境
系统 huawei alp-l29_firmware * Up to (excluding) 9.1.0.315\(c636e5r1p13t8\)
运行在以下环境
系统 huawei berkeley-al20_firmware * Up to (excluding) 9.1.0.333\(c00e333r2p1t8\)
运行在以下环境
系统 huawei berkeley-l09_firmware * Up to (excluding) 9.1.0.350\(c10e3r1p14t8\)
运行在以下环境
系统 huawei berkeley-l09_firmware * Up to (excluding) 9.1.0.350\(c636e4r1p13t8\)
运行在以下环境
系统 huawei berkeley-l09_firmware * Up to (excluding) 9.1.0.351\(c432e5r1p13t8\)
运行在以下环境
系统 huawei bla-l29c_firmware * Up to (excluding) 9.1.0.302\(c635e4r1p13t8\)
运行在以下环境
系统 huawei bla-l29c_firmware * Up to (excluding) 9.1.0.321\(c636e4r1p14t8\)
运行在以下环境
系统 huawei bla-l29c_firmware * Up to (excluding) 9.1.0.330\(c432e6r1p12t8\)
运行在以下环境
系统 huawei charlotte-l09c_firmware * Up to (excluding) 9.1.0.311\(c185e4r1p11t8\)
运行在以下环境
系统 huawei charlotte-l09c_firmware * Up to (excluding) 9.1.0.345\(c432e8r1p11t8\)
运行在以下环境
系统 huawei charlotte-l29c_firmware * Up to (excluding) 9.1.0.325\(c185e4r1p11t8\)
运行在以下环境
系统 huawei charlotte-l29c_firmware * Up to (excluding) 9.1.0.335\(c636e3r1p13t8\)
运行在以下环境
系统 huawei charlotte-l29c_firmware * Up to (excluding) 9.1.0.336\(c605e3r1p12t8\)
运行在以下环境
系统 huawei charlotte-l29c_firmware * Up to (excluding) 9.1.0.345\(c432e8r1p11t8\)
运行在以下环境
系统 huawei columbia-al10b_firmware * Up to (excluding) 9.1.0.333\(c00e333r1p1t8\)
运行在以下环境
系统 huawei columbia-l29d_firmware * Up to (excluding) 9.1.0.350\(c10e5r1p14t8\)
运行在以下环境
系统 huawei columbia-l29d_firmware * Up to (excluding) 9.1.0.350\(c185e3r1p12t8\)
运行在以下环境
系统 huawei columbia-l29d_firmware * Up to (excluding) 9.1.0.350\(c461e3r1p11t8\)
运行在以下环境
系统 huawei columbia-l29d_firmware * Up to (excluding) 9.1.0.351\(c432e5r1p13t8\)
运行在以下环境
系统 huawei cornell-al00a_firmware * Up to (excluding) 9.1.0.333\(c00e333r1p1t8\)
运行在以下环境
系统 huawei cornell-l29a_firmware * Up to (excluding) 9.1.0.328\(c185e1r1p9t8\)
运行在以下环境
系统 huawei cornell-l29a_firmware * Up to (excluding) 9.1.0.328\(c432e1r1p9t8\)
运行在以下环境
系统 huawei cornell-l29a_firmware * Up to (excluding) 9.1.0.328\(c636e2r1p12t8\)
运行在以下环境
系统 huawei cornell-l29a_firmware * Up to (excluding) 9.1.0.330\(c461e1r1p9t8\)
运行在以下环境
系统 huawei emily-l09c_firmware * Up to (excluding) 9.1.0.311\(c185e2r1p12t8\)
运行在以下环境
系统 huawei emily-l09c_firmware * Up to (excluding) 9.1.0.336\(c605e4r1p12t8\)
运行在以下环境
系统 huawei emily-l09c_firmware * Up to (excluding) 9.1.0.345\(c432e10r1p12t8\)
运行在以下环境
系统 huawei emily-l29c_firmware * Up to (excluding) 9.1.0.311\(c432e7r1p11t8\)
运行在以下环境
系统 huawei emily-l29c_firmware * Up to (excluding) 9.1.0.311\(c605e2r1p12t8\)
运行在以下环境
系统 huawei emily-l29c_firmware * Up to (excluding) 9.1.0.311\(c636e7r1p13t8\)
运行在以下环境
系统 huawei ever-l29b_firmware * Up to (excluding) 9.1.0.310\(c432e3r1p12\)
运行在以下环境
系统 huawei ever-l29b_firmware * Up to (excluding) 9.1.0.310\(c636e3r2p1\)
运行在以下环境
系统 huawei ever-l29b_firmware * Up to (excluding) 9.1.0.311\(c185e3r3p1\)
运行在以下环境
系统 huawei honor_10_lite_firmware * Up to (excluding) 9.1.0.283\(c605e8r2p2\)
运行在以下环境
系统 huawei honor_20_firmware * Up to (excluding) 9.1.0.152\(c00e150r5p1\)
运行在以下环境
系统 huawei honor_8x_firmware * Up to (excluding) 9.1.0.221\(c461e2r1p1t8\)
运行在以下环境
系统 huawei honor_magic2_firmware * Up to (excluding) 10.0.0.187
运行在以下环境
系统 huawei honor_v20_firmware * Up to (excluding) 9.1.0.234\(c00e234r4p3\)
运行在以下环境
系统 huawei honor_view_20_firmware * Up to (excluding) 9.1.0.238\(c432e1r3p1\)
运行在以下环境
系统 huawei jackman-l22_firmware * Up to (excluding) 9.1.0.247\(c636e2r4p1t8\)
运行在以下环境
系统 huawei mate_20_firmware * Up to (excluding) 9.1.0.131\(c00e131r3p1\)
运行在以下环境
系统 huawei mate_20_pro_firmware * Up to (excluding) 9.1.0.310\(c185e10r2p1\)
运行在以下环境
系统 huawei mate_20_rs_firmware * Up to (excluding) 9.1.0.135\(c786e133r3p1\)
运行在以下环境
系统 huawei mate_20_x_firmware * Up to (excluding) 9.1.0.135\(c00e133r2p1\)
运行在以下环境
系统 huawei nova_lite_3_firmware * Up to (excluding) 9.1.0.305\(c635e8r2p2\)
运行在以下环境
系统 huawei p20_firmware * Up to (excluding) 9.1.0.333\(c00e333r1p1t8\)
运行在以下环境
系统 huawei p20_pro_firmware * Up to (excluding) 9.1.0.333\(c00e333r1p1t8\)
运行在以下环境
系统 huawei p30_firmware * Up to (excluding) 9.1.0.193
运行在以下环境
系统 huawei p30_pro_firmware * Up to (excluding) 9.1.0.186\(c00e180r2p1\)
运行在以下环境
系统 huawei paris-l21b_firmware * Up to (excluding) 9.1.0.331\(c432e1r1p2t8\)
运行在以下环境
系统 huawei paris-l21meb_firmware * Up to (excluding) 9.1.0.331\(c185e4r1p3t8\)
运行在以下环境
系统 huawei paris-l29b_firmware * Up to (excluding) 9.1.0.331\(c636e1r1p3t8\)
运行在以下环境
系统 huawei sydney-al00_firmware * Up to (excluding) 9.1.0.212\(c00e62r1p7t8\)
运行在以下环境
系统 huawei sydney-l21br_firmware * Up to (excluding) 9.1.0.213\(c185e1r1p2t8\)
运行在以下环境
系统 huawei sydney-l21_firmware * Up to (excluding) 9.1.0.213\(c185e1r1p1t8\)
运行在以下环境
系统 huawei sydney-l21_firmware * Up to (excluding) 9.1.0.215\(c432e1r1p1t8\)
运行在以下环境
系统 huawei sydney-l22br_firmware * Up to (excluding) 9.1.0.258\(c636e1r1p1t8\)
运行在以下环境
系统 huawei sydney-l22_firmware * Up to (excluding) 9.1.0.258\(c636e1r1p1t8\)
运行在以下环境
系统 huawei sydneym-al00_firmware * Up to (excluding) 9.1.0.228\(c00e78r1p7t8\)
运行在以下环境
系统 huawei sydneym-l01_firmware * Up to (excluding) 9.1.0.213\(c185e1r1p1t8\)
运行在以下环境
系统 huawei sydneym-l01_firmware * Up to (excluding) 9.1.0.215\(c782e2r1p1t8\)
运行在以下环境
系统 huawei sydneym-l01_firmware * Up to (excluding) 9.1.0.270\(c432e3r1p1t8\)
运行在以下环境
系统 huawei sydneym-l03_firmware * Up to (excluding) 9.1.0.217\(c605e1r1p1t8\)
运行在以下环境
系统 huawei sydneym-l21_firmware * Up to (excluding) 9.1.0.215\(c432e4r1p1t8\)
运行在以下环境
系统 huawei sydneym-l21_firmware * Up to (excluding) 9.1.0.221\(c461e1r1p1t8\)
运行在以下环境
系统 huawei sydneym-l22_firmware * Up to (excluding) 9.1.0.216\(c569e1r1p1t8\)
运行在以下环境
系统 huawei sydneym-l22_firmware * Up to (excluding) 9.1.0.220\(c635e1r1p2t8\)
运行在以下环境
系统 huawei sydneym-l22_firmware * Up to (excluding) 9.1.0.259\(c185e1r1p2t8\)
运行在以下环境
系统 huawei sydneym-l23_firmware * Up to (excluding) 9.1.0.226\(c605e2r1p1t8\)
运行在以下环境
系统 huawei y9_2019_firmware * Up to (excluding) 9.1.0.220\(c605e3r1p1t8\)
运行在以下环境
系统 huawei yale-l21a_firmware * Up to (excluding) 9.1.0.154\(c432e2r3p2\)
运行在以下环境
系统 huawei yale-l21a_firmware * Up to (excluding) 9.1.0.154\(c461e2r2p1\)
运行在以下环境
系统 huawei yale-l21a_firmware * Up to (excluding) 9.1.0.154\(c636e2r2p1\)
运行在以下环境
硬件 huawei alp-al00b - -
运行在以下环境
硬件 huawei alp-l09 - -
运行在以下环境
硬件 huawei alp-l29 - -
运行在以下环境
硬件 huawei berkeley-al20 - -
运行在以下环境
硬件 huawei berkeley-l09 - -
运行在以下环境
硬件 huawei bla-l29c - -
运行在以下环境
硬件 huawei charlotte-l09c - -
运行在以下环境
硬件 huawei charlotte-l29c - -
运行在以下环境
硬件 huawei columbia-al10b - -
运行在以下环境
硬件 huawei columbia-l29d - -
运行在以下环境
硬件 huawei cornell-al00a - -
运行在以下环境
硬件 huawei cornell-l29a - -
运行在以下环境
硬件 huawei emily-l09c - -
运行在以下环境
硬件 huawei emily-l29c - -
运行在以下环境
硬件 huawei ever-l29b - -
运行在以下环境
硬件 huawei honor_10_lite - -
运行在以下环境
硬件 huawei honor_20 - -
运行在以下环境
硬件 huawei honor_8x - -
运行在以下环境
硬件 huawei honor_magic2 - -
运行在以下环境
硬件 huawei honor_v20 - -
运行在以下环境
硬件 huawei honor_view_20 - -
运行在以下环境
硬件 huawei jackman-l22 - -
运行在以下环境
硬件 huawei mate_20 - -
运行在以下环境
硬件 huawei mate_20_pro - -
运行在以下环境
硬件 huawei mate_20_rs - -
运行在以下环境
硬件 huawei mate_20_x - -
运行在以下环境
硬件 huawei nova_lite_3 - -
运行在以下环境
硬件 huawei p20 - -
运行在以下环境
硬件 huawei p20_pro - -
运行在以下环境
硬件 huawei p30 - -
运行在以下环境
硬件 huawei p30_pro - -
运行在以下环境
硬件 huawei paris-l21b - -
运行在以下环境
硬件 huawei paris-l21meb - -
运行在以下环境
硬件 huawei paris-l29b - -
运行在以下环境
硬件 huawei sydney-al00 - -
运行在以下环境
硬件 huawei sydney-l21 - -
运行在以下环境
硬件 huawei sydney-l21br - -
运行在以下环境
硬件 huawei sydney-l22 - -
运行在以下环境
硬件 huawei sydney-l22br - -
运行在以下环境
硬件 huawei sydneym-al00 - -
运行在以下环境
硬件 huawei sydneym-l01 - -
运行在以下环境
硬件 huawei sydneym-l03 - -
运行在以下环境
硬件 huawei sydneym-l21 - -
运行在以下环境
硬件 huawei sydneym-l22 - -
运行在以下环境
硬件 huawei sydneym-l23 - -
运行在以下环境
硬件 huawei y9_2019 - -
运行在以下环境
硬件 huawei yale-l21a - -
CVSS3评分 5.3
  • 攻击路径 相邻
  • 攻击复杂度 高
  • 权限要求 无
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 高
  • 保密性 无
  • 完整性 无
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-ID 漏洞类型
CWE-20 输入验证不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0