CVE-2024-39612: Background Task Manager has an out-of-bounds read permission bypass vulnerability
Published Sep 2, 2024
·Updated
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
Affected Software
4 affected components
Openatom Openharmony=4.0
Openatom Openharmony=4.0-beta1
Openatom Openharmony=4.0-beta2
Openatom Openharmony=4.0.1
Event History
Sep 2, 2024
CVE Published
via MITRE·03:25 AM
Data Sourced
via MITRE·03:25 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-39612?
CVE-2024-39612 is classified as a medium severity vulnerability due to information leakage risks.
2
How do I fix CVE-2024-39612?
To fix CVE-2024-39612, you should upgrade to the latest version of OpenHarmony beyond v4.0.1.
3
What types of attacks can be executed due to CVE-2024-39612?
CVE-2024-39612 allows local attackers to perform information leakage attacks through out-of-bounds reads.
4
Which versions of OpenHarmony are affected by CVE-2024-39612?
OpenHarmony v4.0.0 and prior versions including v4.0-beta1, v4.0-beta2, and v4.0.1 are affected by CVE-2024-39612.
5
Who is impacted by CVE-2024-39612?
Users and organizations utilizing affected versions of OpenHarmony are at risk of exploitation due to CVE-2024-39612.