Stack Overflow Bug in ofono's Decode_Deliver_Report Function Could Lead to SMS Attacks
CVE-2023-4235
8.1HIGH
What is CVE-2023-4235?
A stack overflow vulnerability exists in ofono, an Open Source Telephony software for Linux, specifically within the decode_deliver_report() function utilized during SMS decoding. This flaw can be exploited under scenarios involving a compromised modem or via a malicious base station. The vulnerability occurs due to a missing bounds check in the memcpy operation leading to potentially dangerous memory access. While examine protocols, application developers and administrators are urged to stay vigilant against possible attacks leveraging this flaw.
Affected Version(s)
ofono 2.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Mitch Zakocs (Trend Micro Zero Day Initiative) for reporting this issue.
