Impact
The vulnerability lies in smpp34_unpack() where an out-of-bounds read can corrupt memory when parsing SMPP PDUs. The description indicates that malformed or oversized PDUs trigger the issue. While the description does not explicitly state the outcome, it is inferred that the corruption could result in a process crash and potentially allow unintended code execution depending on the surrounding memory layout.
Affected Systems
The flaw affects Osmocom libsmpp34 across versions 0.1.0 to 1.8.0 inclusive. Systems that rely on this library to process SMPP traffic, such as telecommunications infrastructure or VoIP gateways implementing OSMO_SL functions, are at risk unless they run a later revision.
Risk and Exploitability
The defect is an out-of-bounds read; an attacker may exploit it by sending crafted SMPP PDUs to a vulnerable instance. The description does not mention authentication requirements, so it is inferred that no special credentials are needed. The CVSS score of 7.5 indicates a high severity, while the EPSS score of <1% suggests a low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog and no public exploits are reported.
OpenCVE Enrichment
Debian DLA