CVE-2023-4232 is a high-severity stack overflow vulnerability in the decode_status_report() function of oFono, an Open Source Telephony on Linux, affecting fedoraproject and ofono_project distributions. The flaw, rated 8.1 HIGH on CVSS, can be triggered by a compromised modem, malicious base station, or specially crafted SMS, allowing for high impact to confidentiality, integrity, and availability. While the attack complexity is high, no active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage has been observed for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE match | cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:* | ||
< 2.1CPE matchmatch criteria | cpe:2.3:a:ofono_project:ofono:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* | ||
40CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.