CVE-2023-49135: multimedia player has a UAF vulnerability
Published Jan 2, 2024
·Updated
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause multimedia player crash through modify a released pointer.
Affected Software
1 affected component
Openatom Openharmony<=3.2.2
Event History
Jan 2, 2024
CVE Published
07:24 AM
Data Sourced
07:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-49135?
CVE-2023-49135 has been classified as a high-severity vulnerability due to the potential for a local attacker to crash the multimedia player.
2
How do I fix CVE-2023-49135?
Fixing CVE-2023-49135 involves updating to OpenHarmony version 3.2.3 or later where the vulnerability is addressed.
3
What impact does CVE-2023-49135 have on affected systems?
CVE-2023-49135 can lead to denial of service on multimedia player applications, potentially causing system instability.
4
Who is at risk from CVE-2023-49135?
Local users of OpenHarmony versions up to 3.2.2 are at risk of exploitation through this vulnerability.
5
Is there a known exploit for CVE-2023-49135?
As of now, there are no publicly reported exploits specifically targeting CVE-2023-49135.