Bug ID 1228917
Summary VUL-0: CVE-2024-7547: ofono:
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/416433/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee mpluskal@suse.com
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

oFono SMS Decoder Stack-based Buffer Overflow Privilege Escalation
Vulnerability. This vulnerability allows local attackers to execute arbitrary
code on affected installations of oFono. An attacker must first obtain the
ability to execute code on the target modem in order to exploit this
vulnerability.

The specific flaw exists within the parsing of SMS PDUs. The issue results from
the lack of proper validation of the length of user-supplied data prior to
copying it to a stack-based buffer. An attacker can leverage this vulnerability
to execute code in the context of the service account. Was ZDI-CAN-23460.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-7547
https://www.cve.org/CVERecord?id=CVE-2024-7547
http://www.zerodayinitiative.com/advisories/ZDI-24-1087/
https://bugzilla.redhat.com/show_bug.cgi?id=2303010


You are receiving this mail because: