{"id":"UBUNTU-CVE-2024-25763","details":"openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.","modified":"2026-02-04T02:39:14.017370Z","published":"2024-02-26T16:27:00Z","related":["USN-7312-1"],"upstream":["CVE-2024-25763"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-25763"},{"type":"REPORT","url":"https://github.com/LuMingYinDetect/openNDS_defects/blob/main/openNDS_detect_1.md"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-25763"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7312-1"}],"affected":[{"package":{"name":"opennds","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/opennds@10.2.0+dfsg-1ubuntu0.24.04.1~esm1?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.2.0+dfsg-1ubuntu0.24.04.1~esm1"}]}],"versions":["9.10.0-1","10.2.0+dfsg-1","10.2.0+dfsg-1build1","10.2.0+dfsg-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"opennds","binary_version":"10.2.0+dfsg-1ubuntu0.24.04.1~esm1"},{"binary_name":"opennds-daemon","binary_version":"10.2.0+dfsg-1ubuntu0.24.04.1~esm1"},{"binary_name":"opennds-daemon-common","binary_version":"10.2.0+dfsg-1ubuntu0.24.04.1~esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-25763.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]}