mailing list archives
SMS handling OpenSER remote code executing
From: sapheal () hack pl
Date: Thu, 28 Dec 2006 14:09:00 +0100
Synopsis: SMS handling OpenSER remote code executing
A critical security vulnerability has been found in OpenSER SMS
handling module. The vulnerable function should read the SMS
from the SIM-memory.
int fetchsms(struct modem *mdm, int sim, char* pdu)
The usage of this fuction might lead to memory corruption
conditions. Due to memory corruption conditions remote
code execution is possible. It happens when "beginning"
is copied to functions argument PDU (char*).
OpenSER <= 1.1.0
Proper boundary checking.
Exploitation might be conducted by preparing a specially
crafted SMS message.
- SMS handling OpenSER remote code executing sapheal (Dec 28)