CVE-2023-25947: The bundle management subsystem has a improper input validation when installing a HAP package.
The bundle management subsystem within OpenHarmony-v3.1.4 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause a DoS attack to the system when installing a malicious HAP package.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-25947?
CVE-2023-25947 is a null pointer reference vulnerability in the bundle management subsystem within OpenHarmony-v3.1.4 and prior versions.
How does CVE-2023-25947 affect the system?
CVE-2023-25947 allows local attackers to exploit the vulnerability by installing a malicious HAP package, causing a denial-of-service (DoS) attack on the system.
What is the severity of CVE-2023-25947?
CVE-2023-25947 has a severity rating of 5.5, which is considered medium.
How can I fix CVE-2023-25947?
To fix CVE-2023-25947, it is recommended to update OpenHarmony to version 3.1.5 or later, which includes a patch for this vulnerability.
Where can I find more information about CVE-2023-25947?
You can find more information about CVE-2023-25947 in the OpenHarmony security disclosure document at https://gitee.com/openharmony/security/blob/master/en/security-disclosure/2023/2023-03.md.