CVE-2023-41102

An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:*

History

21 Nov 2024, 08:20

Type Values Removed Values Added
References () https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51 - Patch () https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51 - Patch
References () https://github.com/openNDS/openNDS/releases/tag/v10.1.3 - Release Notes () https://github.com/openNDS/openNDS/releases/tag/v10.1.3 - Release Notes
References () https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89 - () https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89 -
References () https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs - () https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs -

03 Jul 2024, 01:41

Type Values Removed Values Added
CWE CWE-400

20 Jun 2024, 18:15

Type Values Removed Values Added
References
  • () https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89 -
  • () https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs -
Summary (en) An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. (en) An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.

25 Nov 2023, 02:15

Type Values Removed Values Added
CWE CWE-401
First Time Opennds opennds
Opennds
CPE cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51 - () https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51 - Patch
References () https://github.com/openNDS/openNDS/releases/tag/v10.1.3 - () https://github.com/openNDS/openNDS/releases/tag/v10.1.3 - Release Notes

17 Nov 2023, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-17 06:15

Updated : 2024-11-21 08:20


NVD link : CVE-2023-41102

Mitre link : CVE-2023-41102

CVE.ORG link : CVE-2023-41102


JSON object : View

Products Affected

opennds

  • opennds
CWE
CWE-401

Missing Release of Memory after Effective Lifetime

CWE-400

Uncontrolled Resource Consumption