{"id":"CVE-2024-52296","summary":"libosdp has a null pointer deref in osdp_reply_name","details":"libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust and Python3. At ospd_common.c, on the osdp_reply_name function, any reply id between REPLY_ACK and REPLY_XRD is valid, but names array do not declare all of the range. On a case of an undefined reply id within the range, name will be null (name = names[reply_id - REPLY_ACK];). Null name will casue a crash on next line: if (name[0] == '\\0') as null[0] is invalid. As this logic is not limited to a secure connection, attacker may trigger this vulnerability without any prior knowledge. This issue is fixed in 2.4.0.","aliases":["GHSA-7945-5mcv-f2pp","PYSEC-2026-1534"],"modified":"2026-08-12T15:16:07.045854Z","published":"2024-11-12T15:58:28.434Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52296.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-476"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52296.json"},{"type":"ADVISORY","url":"https://github.com/goToMain/libosdp/security/advisories/GHSA-7945-5mcv-f2pp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52296"},{"type":"FIX","url":"https://github.com/goToMain/libosdp/commit/24409e98a260176765956ec766a04cb35984fab1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/osdp-dev/libosdp","events":[{"introduced":"0"},{"fixed":"24409e98a260176765956ec766a04cb35984fab1"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.4.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v2.3.0","v2.2.0","v2.1.0","v2.0.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v1.0.0","v0.4","v0.3","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52296.json","vanir_signatures_modified":"2026-08-12T15:16:07Z","vanir_signatures":[{"target":{"file":"src/osdp_common.c","function":"osdp_reply_name"},"deprecated":false,"digest":{"function_hash":"19324216122283965346011263709911722834","length":1256},"id":"CVE-2024-52296-42013ff3","signature_type":"Function","signature_version":"v1","source":"https://github.com/osdp-dev/libosdp/commit/24409e98a260176765956ec766a04cb35984fab1"},{"signature_version":"v1","source":"https://github.com/osdp-dev/libosdp/commit/24409e98a260176765956ec766a04cb35984fab1","target":{"file":"src/osdp_common.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["286553202551388732001541327239852901514","89303886345137972058415696300314905153","253743706143264485288515863695414304367","271158803284206351798783790510864310014"]},"id":"CVE-2024-52296-bb0f4995","signature_type":"Line"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}