CVE-2024-38382: Ability Runtime has an out-of-bounds read permission bypass vulnerability
Published Sep 2, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
Affected Software
4 affected components
Openatom Openharmony=4.0
Openatom Openharmony=4.0-beta1
Openatom Openharmony=4.0-beta2
Openatom Openharmony=4.0.1
Event History
Sep 2, 2024
CVE Published
via MITRE·03:24 AM
Data Sourced
via MITRE·03:24 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38382?
The severity of CVE-2024-38382 is considered moderate due to the potential for information leakage.
2
How do I fix CVE-2024-38382?
To fix CVE-2024-38382, update OpenHarmony to version 4.0.1 or later.
3
Who is affected by CVE-2024-38382?
CVE-2024-38382 affects local users of OpenHarmony versions 4.0.0, 4.0-beta1, 4.0-beta2, and 4.0.1.
4
What type of vulnerability is CVE-2024-38382?
CVE-2024-38382 is an information leak vulnerability caused by an out-of-bounds read.
5
Can CVE-2024-38382 be exploited remotely?
No, CVE-2024-38382 requires local access to the affected system to be exploited.