CVE-2022-36423: Incorrect configuration of the cJSON library lead a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.
Published Sep 9, 2022
·Updated
OpenHarmony-v3.1.2 and prior versions have an incorrect configuration of the cJSON library, which leads a Stack overflow vulnerability during recursive parsing. LAN attackers can lead a DoS attack to all network devices.
Affected Software
4 affected components
OpenHarmony OpenHarmony>=1.1.0<=1.1.5
OpenHarmony OpenHarmony>=3.0<=3.0.5
OpenHarmony OpenHarmony>=3.1<=3.1.2
Openatom Openharmony>=3.1<=3.1.2
Event History
Sep 9, 2022
CVE Published
via MITRE·02:39 PM
Data Sourced
via MITRE·02:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-36423.
2
What is the severity of CVE-2022-36423?
The severity of CVE-2022-36423 is high.
3
What is the affected software for CVE-2022-36423?
The affected software for CVE-2022-36423 is OpenHarmony-v3.1.2 and prior versions.
4
What is the impact of CVE-2022-36423?
CVE-2022-36423 can lead to a Denial of Service (DoS) attack on all network devices.
5
Is there a fix available for CVE-2022-36423?
A fix for CVE-2022-36423 is not mentioned in the provided information.