Stack Overflow Bug in ofono Affects SMS Decoding
CVE-2023-4233
8.1HIGH
What is CVE-2023-4233?
A stack overflow vulnerability exists in Ofono, an open-source telephony framework for Linux. This issue arises within the sms_decode_address_field() function during the SMS Protocol Data Unit (PDU) decoding, potentially allowing an attacker to exploit conditions via a compromised modem, a malicious base station, or by transmitting crafted SMS messages. Addressing this flaw is crucial to ensure the security and integrity of telephony communications.
Affected Version(s)
ofono 2.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Mitch Zakocs (Trend Micro Zero Day Initiative) for reporting this issue.
