Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-7540

Опубликовано: 06 авг. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 3.3

Описание

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CMGL commands. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23307.

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps-legacy/xenial

released

1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm3
esm-apps/bionic

released

1.21-1ubuntu1+esm3
esm-apps/focal

released

1.31-2ubuntu1+esm3
esm-apps/jammy

released

1.31-3ubuntu1.2+esm1
esm-apps/noble

released

1.31-3ubuntu3.24.04.2+esm1
esm-apps/resolute

not-affected

code not present
esm-apps/xenial

released

1.17.bzr6912+16.04.20160314.3-0ubuntu1+esm3
focal

ignored

end of standard support, was needs-triage
jammy

needed

Показывать по

EPSS

Процентиль: 22%
0.00297
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
nvd
около 2 лет назад

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CMGL commands. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23307.

CVSS3: 3.3
debian
около 2 лет назад

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vu ...

CVSS3: 3.3
github
около 2 лет назад

oFono AT CMGL Command Uninitialized Variable Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of oFono. An attacker must first obtain the ability to execute code on the target modem in order to exploit this vulnerability. The specific flaw exists within the parsing of responses from AT+CMGL commands. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-23307.

suse-cvrf
около 2 месяцев назад

Security update for ofono

EPSS

Процентиль: 22%
0.00297
Низкий

3.3 Low

CVSS3