Stack Overflow Bug in ofono Affects SMS Decoding
CVE-2023-4234
8.1HIGH
What is CVE-2023-4234?
A vulnerability exists in the ofono open-source telephony software for Linux, specifically within the decode_submit_report() function. This stack overflow issue arises during the decoding of SMS messages, potentially allowing remote code execution through manipulation of inputs from compromised modems, malicious base stations, or through crafted SMS messages. Although a bound check is implemented in the decode_submit() function, it has not been carried over to decode_submit_report(), resulting in a security gap that can be exploited. Further details can be found in the related issue tracking report here.
Affected Version(s)
ofono 2.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Mitch Zakocs (Trend Micro Zero Day Initiative) for reporting this issue.