ZDI-23-1859: oFono SMS Decoder Stack-based Buffer Overflow Remote Code Execution Vulnerability
Published Dec 20, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of oFono. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2023-4233.
Affected Software
1 affected component
oFono oFono
Event History
Dec 20, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-23-1859?
The severity of ZDI-23-1859 is rated at 8.1 on the CVSS scale.
2
How do I fix ZDI-23-1859?
To fix ZDI-23-1859, ensure that you update oFono to the patched version released by the vendor.
3
What type of attack can exploit ZDI-23-1859?
ZDI-23-1859 can be exploited through a stack-based buffer overflow leading to remote code execution.
4
Does ZDI-23-1859 require authentication to exploit?
No, ZDI-23-1859 does not require authentication to exploit.
5
Which software is affected by ZDI-23-1859?
ZDI-23-1859 affects installations of oFono.