CVE-2024-12082: Ability Runtime has an out-of-bounds read permission bypass vulnerability
Published Dec 3, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
Affected Software
1 affected component
Openatom Openharmony<=4.0
Event History
Dec 3, 2024
CVE Published
via MITRE·12:15 PM
Data Sourced
via MITRE·12:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-12082?
The severity of CVE-2024-12082 is classified as moderate due to the potential for information leakage.
2
How do I fix CVE-2024-12082?
To fix CVE-2024-12082, update OpenHarmony to version 4.0.1 or later where the vulnerability has been addressed.
3
Who is affected by CVE-2024-12082?
CVE-2024-12082 affects all local users of OpenHarmony versions 4.0.0 and earlier.
4
What kind of information is leaked by CVE-2024-12082?
CVE-2024-12082 may lead to an information leak that could expose sensitive data from memory through out-of-bounds reads.
5
Is CVE-2024-12082 a remote vulnerability?
No, CVE-2024-12082 is a local vulnerability that requires access to the system to exploit.