Stack Overflow Bug in ofono Affects SMS Decoding
CVE-2023-4233

8.1HIGH

Key Information:

Vendor

Fedora

Vendor
CVE Published:
17 April 2024

What is CVE-2023-4233?

A stack overflow vulnerability exists in Ofono, an open-source telephony framework for Linux. This issue arises within the sms_decode_address_field() function during the SMS Protocol Data Unit (PDU) decoding, potentially allowing an attacker to exploit conditions via a compromised modem, a malicious base station, or by transmitting crafted SMS messages. Addressing this flaw is crucial to ensure the security and integrity of telephony communications.

Affected Version(s)

ofono 2.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Mitch Zakocs (Trend Micro Zero Day Initiative) for reporting this issue.
.