漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Out-of-bound memory read and write in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The proc ...
Vulnerability Description
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
跨界内存写
Vulnerability Title
OpenHarmony 缓冲区错误漏洞
Vulnerability Description
OpenHarmony是中国OpenAtom Foundation基金会的一种鸿蒙操作系统的开源项目。 OpenHarmony v3.1.2及以前版本和3.0.6及以前版本存在安全漏洞,该漏洞源于其/dev/mmz_userdev设备驱动程序内存越界读写导致设备上运行的非特权进程可以读取未绑定的内存实现敏感的信息泄露。或在设备上运行的具有系统用户UID的进程将能够写入未绑定的内存可能导致未指定的内存损坏。上述两种攻击方式取决于攻击者的权限。
CVSS Information
N/A
Vulnerability Type
N/A