Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. libosdp
  4. ›
  5. GHSA-7945-5mcv-f2pp

GHSA-7945-5mcv-f2pp: LibOSDP vulnerable to a null pointer deref in osdp_reply_name

March 8, 2024

Issue:

At ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid, but names array do not declare all of the range. On a case of an undefined reply id within the range, name will be null (name = names[reply_id - REPLY_ACK];). Null name will casue a crash on next line: if (name[0] == '\0') as null[0] is invalid.

Attack:

As this logic is not limited to a secure connection, attacker may trigger this vulnerability without any prior knowledge.

Impact

Denial of Service

Patch

The issue has been patched in 24409e98a260176765956ec766a04cb35984fab1

References

  • github.com/advisories/GHSA-7945-5mcv-f2pp
  • github.com/goToMain/libosdp
  • github.com/goToMain/libosdp/commit/24409e98a260176765956ec766a04cb35984fab1
  • github.com/goToMain/libosdp/security/advisories/GHSA-7945-5mcv-f2pp

Code Behaviors & Features

Detect and mitigate GHSA-7945-5mcv-f2pp with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.4.0

Fixed versions

  • 2.4.0

Solution

Upgrade to version 2.4.0 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Source file

pypi/libosdp/GHSA-7945-5mcv-f2pp.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:23 +0000.