CVE-2024-25763: Use After Free
Last updated 3 March 2025
Other sources
openNDS 10.2.0 is vulnerable to Use-After-Free via /openNDS/src/auth.c.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openndsto a version that resolves this vulnerability.Fixed in 10.3.0+dfsg-0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25763?
CVE-2024-25763 has been categorized with a high severity rating due to the potential for exploitation via Use-After-Free vulnerabilities.
How do I fix CVE-2024-25763?
To fix CVE-2024-25763, upgrade to version 10.3.0+dfsg-0.1 or later of the openNDS software.
What systems are affected by CVE-2024-25763?
CVE-2024-25763 affects openNDS version 10.2.0 and older versions up to 9.10.0-1.
Can CVE-2024-25763 be exploited remotely?
Yes, CVE-2024-25763 can be exploited remotely, allowing attackers to execute arbitrary code under certain conditions.
What is the cause of the CVE-2024-25763 vulnerability?
The CVE-2024-25763 vulnerability is caused by improper handling of memory through a Use-After-Free issue in the auth.c file.