CVE-2023-41102

An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:*

History

20 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89 -
  • () https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs -
Summary An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.

25 Nov 2023, 02:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:*
First Time Opennds
Opennds opennds
CWE CWE-401
References () https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51 - () https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51 - Patch
References () https://github.com/openNDS/openNDS/releases/tag/v10.1.3 - () https://github.com/openNDS/openNDS/releases/tag/v10.1.3 - Release Notes

17 Nov 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-17 06:15

Updated : 2024-07-03 01:41


NVD link : CVE-2023-41102

Mitre link : CVE-2023-41102


JSON object : View

Products Affected

opennds

  • opennds
CWE
CWE-401

Missing Release of Memory after Effective Lifetime