NULL Pointer Dereference
CVE-2024-52296
Summary
The libosdp is an implementation of IEC 60839-11-5 OSDP (Open Supervised Device Protocol) and provides a C library with support for C++, Rust, and Python3. In the file "ospd_common.c", within the "osdp_reply_name" function, any reply id between REPLY_ACK and REPLY_XRD is valid, but the names array does not declare all of the range. On a case of an undefined reply id within the range, the name will be null (name = names[reply_id - REPLY_ACK];). Null name will cause a crash on the next line: if (name[0] == '\0') as null[0] is invalid. As this logic is not limited to a secure connection, an attacker may trigger this vulnerability without any prior knowledge. This issue affects libosdp versions prior to 2.4.0.
- LOW
- ADJACENT NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-476 - NULL Pointer Dereference
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
References
Advisory Timeline
- Published