OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.
Weaknesses in this category are typically introduced during the configuration of the software.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2022/2022-09.md | third party advisory |