Stack Overflow Bug in ofono's Decode_Deliver_Report Function Could Lead to SMS Attacks
CVE-2023-4235
What is CVE-2023-4235?
A stack overflow vulnerability exists in ofono, an Open Source Telephony software for Linux, specifically within the decode_deliver_report() function utilized during SMS decoding. This flaw can be exploited under scenarios involving a compromised modem or via a malicious base station. The vulnerability occurs due to a missing bounds check in the memcpy operation leading to potentially dangerous memory access. While examine protocols, application developers and administrators are urged to stay vigilant against possible attacks leveraging this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ofono 2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
