USN-7141-1: oFono vulnerabilities
It was discovered that oFono incorrectly handled decoding SMS messages leading to a stack overflow. A remote attacker could potentially use this issue to cause a denial of service. (CVE-2023-2794, CVE-2023-4233, CVE-2023-4234)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7141-1?
The USN-7141-1 vulnerability is a critical issue that could lead to denial of service due to a stack overflow in oFono.
How can I fix USN-7141-1?
To resolve USN-7141-1, update oFono to the recommended patched version for your Ubuntu release.
What products are affected by USN-7141-1?
USN-7141-1 affects various versions of Ubuntu including 20.04, 22.04, 24.04, and 24.10 with specific oFono package versions.
What types of attacks can exploit USN-7141-1?
An attacker can exploit USN-7141-1 by sending specially crafted SMS messages that trigger the stack overflow.
Is there a known CVE associated with USN-7141-1?
Yes, USN-7141-1 is associated with multiple CVEs including CVE-2023-2794, CVE-2023-4233, and CVE-2023-4234.