PT-2022-23361 · Cjson+1 · Cjson+1
Published
2022-09-09
·
Updated
2024-09-09
·
CVE-2022-36423
CVSS v3.1
7.4
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OpenHarmony versions prior to 3.1.2
Description
The issue is caused by an incorrect configuration of the cJSON library, leading to a stack overflow vulnerability during recursive parsing. This allows LAN attackers to launch a Denial of Service (DoS) attack against all network devices.
Recommendations
For OpenHarmony versions prior to 3.1.2, update to a version that correctly configures the cJSON library to prevent the stack overflow vulnerability.
As a temporary workaround, consider restricting access to the network to minimize the risk of exploitation by LAN attackers.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openharmony
Cjson