CVE-2023-4232
published 2024-04-17CVE-2023-4232: A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS…
PriorityP348high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.95%
57.2th percentile
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ofono | < ofono 2.14-1 (forky) | ofono 2.14-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| ofono_project | ofono | < 2.1 | 2.1 |
| ofono_project | ofono | >= 0 < 2.14-1 | 2.14-1 |
| ofono_project | ofono | >= 0 < 2.14-1 | 2.14-1 |
| ofono_project | ofono | >= 0 < 1.31-3ubuntu1.2 | 1.31-3ubuntu1.2 |
| ofono_project | ofono | >= 0 < 1.31-3ubuntu3.24.04.2 | 1.31-3ubuntu3.24.04.2 |
| ofono_project | ofono | >= 0 < 1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm2 | 1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm2 |
| ofono_project | ofono | >= 0 < 1.21-1ubuntu1+esm2 | 1.21-1ubuntu1+esm2 |
| ofono_project | ofono | >= 0 < 1.31-2ubuntu1+esm2 | 1.31-2ubuntu1+esm2 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_ubuntu8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
oFono vulnerabilities
vendor_ubuntu·2024-12-11·CVSS 8.1
CVE-2023-4235 [HIGH] oFono vulnerabilities
Title: oFono vulnerabilities
Summary: Several security issues were fixed in ofono.
It was discovered that oFono incorrectly handled decoding SMS messages
leading to a stack overflow. A remote attacker could potentially use
this issue to cause a denial of service. (CVE-2023-4232, CVE-2023-4235)
Instructions: After a standard system update you need to restart oFono to make
all the necessary changes.
Debian
CVE-2023-4232: ofono - A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow b...
vendor_debian·2023·CVSS 8.1
CVE-2023-4232 [HIGH] CVE-2023-4232: ofono - A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow b...
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14-1)
sid: resolved (fixed in 2.14-1)
trixie: resolved (fixed in 2.14-1)
OSV
ofono vulnerabilities
osv·2024-12-11·CVSS 8.1
CVE-2023-4232 [HIGH] ofono vulnerabilities
ofono vulnerabilities
It was discovered that oFono incorrectly handled decoding SMS messages
leading to a stack overflow. A remote attacker could potentially use
this issue to cause a denial of service. (CVE-2023-4232, CVE-2023-4235)
GHSA
GHSA-7hc5-mgqg-mvrm: A flaw was found in ofono, an Open Source Telephony on Linux
ghsa_unreviewed·2024-04-18
CVE-2023-4232 [HIGH] CWE-119 GHSA-7hc5-mgqg-mvrm: A flaw was found in ofono, an Open Source Telephony on Linux
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().
OSV
CVE-2023-4232: A flaw was found in ofono, an Open Source Telephony on Linux
osv·2024-04-17·CVSS 8.1
CVE-2023-4232 [HIGH] CVE-2023-4232: A flaw was found in ofono, an Open Source Telephony on Linux
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was forgotten in decode_status_report().
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-17
Published