mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
18 lines
887 B
Markdown
18 lines
887 B
Markdown
### [CVE-2023-38320](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38320)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). This problem was fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/DiRaltvein/memory-corruption-examples
|
|
|