{"id":"CVE-2023-41102","details":"An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.","modified":"2026-08-12T13:32:42.613833Z","published":"2023-11-17T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41102.json"},"references":[{"type":"WEB","url":"https://github.com/openNDS/openNDS/releases/tag/v10.1.3"},{"type":"WEB","url":"https://source.sierrawireless.com/resources/security-bulletins/sierra-wireless-technical-bulletin---swi-psa-2023-006-v4/#sthash.2vJg3d85.rwx82g1C.dpbs"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/41xxx/CVE-2023-41102.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41102"},{"type":"FIX","url":"https://github.com/openNDS/openNDS/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51"},{"type":"FIX","url":"https://github.com/openwrt/routing/commit/ad787a920ccb9dacf5b01d52bce36ac14a5ecd89"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/opennds/opennds","events":[{"introduced":"0"},{"fixed":"69dde77927b252e2a4347170504a785ac5d50c33"},{"fixed":"31dbf4aa069c5bb39a7926d86036ce3b04312b51"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:opennds:opennds:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"10.1.3"}]}},{"type":"GIT","repo":"https://github.com/openwrt/routing","events":[{"introduced":"0"},{"fixed":"ad787a920ccb9dacf5b01d52bce36ac14a5ecd89"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v10.1.3","v10.1.2","v10.1.1","v10.1.0","v9.10.0","v9.9.1","v9.9.0","v9.8.0","v9.7.0","v9.6.0","v9.5.1","v9.5.0","v9.4.0","v9.3.0","v9.2.0","v9.1.1","v9.1.0","v9.0.0","v8.1.1","v8.1.0","v8.0.0","v7.0.1","v7.0.0","v6.0.0","v5.2.0","v5.1.0","v5.0.1","v5.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-41102.json","vanir_signatures_modified":"2026-08-12T13:32:42Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/opennds/opennds/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51","target":{"function":"client_reset","file":"src/client_list.c"},"deprecated":false,"digest":{"function_hash":"114453890567834647965685719824587767951","length":1004},"id":"CVE-2023-41102-04d8882d"},{"signature_version":"v1","source":"https://github.com/opennds/opennds/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51","target":{"file":"src/client_list.c","function":"_client_list_free_node"},"deprecated":false,"digest":{"function_hash":"111946994257986523736346573010147181776","length":376},"id":"CVE-2023-41102-5ea0e821","signature_type":"Function"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/opennds/opennds/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51","target":{"file":"src/client_list.c"},"deprecated":false,"digest":{"line_hashes":["309883865822656205120904230157861152430","218641413411637046584653299465956762644","154366200437616714995018179146879283151","167054071320135631185158432643977228813","220378641845672108835288240462172789641","257828874008015060487122637993844471292","119183715455682742955387468425165022393","109310709702527705998561615116592252579","246038276234997406492972260729425314106","107248104420302283145201838074675470581","48527951882261810520248555341589741123","188970831149681757312628630391965456395","24056457945855280061205702776546777664"],"threshold":0.9},"id":"CVE-2023-41102-77324f52"},{"signature_version":"v1","source":"https://github.com/opennds/opennds/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51","target":{"file":"src/http_microhttpd.c"},"deprecated":false,"digest":{"line_hashes":["204580094829658141876247396546241413979","53959168667521409563875410821839881076","139372920570885686454043986697294147601","91224663760601915698346904270031756370","282530142551032988576917341017649734939"],"threshold":0.9},"id":"CVE-2023-41102-d2da72df","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"328333231479874028419759832420785874083","length":1485},"id":"CVE-2023-41102-dcb802ba","signature_type":"Function","signature_version":"v1","source":"https://github.com/opennds/opennds/commit/31dbf4aa069c5bb39a7926d86036ce3b04312b51","target":{"file":"src/http_microhttpd.c","function":"redirect_to_splashpage"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}