USN-7151-1: oFono vulnerabilities
Published Dec 11, 2024
·Updated
It was discovered that oFono incorrectly handled decoding SMS messages leading to a stack overflow. A remote attacker could potentially use this issue to cause a denial of service. (CVE-2023-4232, CVE-2023-4235)
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/ofono<1.31-3ubuntu3.24.10.2
1.31-3ubuntu3.24.10.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/ofono<1.31-3ubuntu3.24.04.2
1.31-3ubuntu3.24.04.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/ofono<1.31-3ubuntu1.2
1.31-3ubuntu1.2
Ubuntu Ubuntu=22.04
All of the following
ubuntu/ofono<1.31-2ubuntu1+esm2
1.31-2ubuntu1+esm2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/ofono<1.21-1ubuntu1+esm2
1.21-1ubuntu1+esm2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/ofono<1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm2
1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm2
Ubuntu Ubuntu=16.04
Event History
Dec 11, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7151-1?
The severity of USN-7151-1 is categorized as a denial of service vulnerability due to a stack overflow in oFono.
2
How do I fix USN-7151-1?
To fix USN-7151-1, you should upgrade oFono to the latest version available for your Ubuntu release.
3
Which Ubuntu versions are affected by USN-7151-1?
USN-7151-1 affects multiple Ubuntu versions including 24.10, 24.04, 22.04, 20.04, 18.04, and 16.04.
4
What components are impacted by USN-7151-1?
USN-7151-1 primarily impacts the oFono package responsible for handling SMS messages.
5
Can USN-7151-1 be exploited remotely?
Yes, a remote attacker could potentially exploit USN-7151-1 to cause a denial of service.