CVE-2025-0303: Liteos_a has a buffer overflow vulnerability
Published Feb 7, 2025
·Updated
in OpenHarmony v4.1.2 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through buffer overflow.
Affected Software
2 affected components
OpenHarmony OpenHarmony<4.1.2
Openatom Openharmony>=4.1.0<=4.1.2
Event History
Feb 7, 2025
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-0303?
CVE-2025-0303 is considered a high severity vulnerability due to its potential for local exploitation and root privilege escalation.
2
How do I fix CVE-2025-0303?
To fix CVE-2025-0303, upgrade OpenHarmony to version 4.1.3 or later.
3
What systems are affected by CVE-2025-0303?
CVE-2025-0303 affects OpenHarmony versions up to and including 4.1.2.
4
What type of attack can be executed using CVE-2025-0303?
A local attacker can exploit CVE-2025-0303 to upgrade common permissions to root and leak sensitive information.
5
Is CVE-2025-0303 a remote or local vulnerability?
CVE-2025-0303 is a local vulnerability, requiring access to the system for exploitation.