HomeDefectsLIN1022-7648
Fixed

LIN1022-7648 : Security Advisory - ofono - CVE-2023-4233

Created: Apr 17, 2024    Updated: Jun 27, 2024
Resolved Date: Jun 26, 2024
Found In Version: 10.22.33.1
Fix Version: 10.22.33.17
Severity: Standard
Applicable for: Wind River Linux LTS 22
Component/s: Userspace

Description

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_address_field() function during the SMS PDU decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS.

CREATE(Triage):(User=admin) CVE-2023-4233 (https://nvd.nist.gov/vuln/detail/CVE-2023-4233)

CVEs