Stack Overflow Bug in ofono Affects SMS Decoding
CVE-2023-4234
What is CVE-2023-4234?
A vulnerability exists in the ofono open-source telephony software for Linux, specifically within the decode_submit_report() function. This stack overflow issue arises during the decoding of SMS messages, potentially allowing remote code execution through manipulation of inputs from compromised modems, malicious base stations, or through crafted SMS messages. Although a bound check is implemented in the decode_submit() function, it has not been carried over to decode_submit_report(), resulting in a security gap that can be exploited. Further details can be found in the related issue tracking report here.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ofono 2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
