Loading HuntDB...

GHSA-596w-g2cr-x93q

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth option is set.

Related CVEs

Key Information

GHSA ID
GHSA-596w-g2cr-x93q
Published
November 17, 2023 6:31 AM
Last Modified
June 20, 2024 6:34 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.