Debian Package Tracker
Register | Log in
Subscribe

opennds

manage access to public internet access

Choose email to subscribe with

general
  • source: opennds (main)
  • version: 10.3.1+dfsg-1
  • maintainer: Debian Edu Packaging Team (archive) (DMD)
  • uploaders: Mike Gabriel [DMD] – Daniel Teichmann [DMD]
  • arch: all any
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 9.10.0-1
  • stable: 10.3.1+dfsg-1
  • testing: 10.3.1+dfsg-1
  • unstable: 10.3.1+dfsg-1
versioned links
  • 9.10.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 10.3.1+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • opennds
  • opennds-daemon (1 bugs: 0, 1, 0, 0)
  • opennds-daemon-common
action needed
Marked for autoremoval on 03 October: #1146716 high
Version 10.3.1+dfsg-1 of opennds is marked for autoremoval from testing on Sat 03 Oct 2026. It is affected by #1146716. You should try to prevent the removal by fixing these RC bugs.
Created: 2026-09-11 Last update: 2026-09-13 07:31
A new upstream version is available: 11.0.0 high
A new upstream version 11.0.0 is available, you should consider packaging it.
Created: 2026-04-23 Last update: 2026-09-13 07:02
4 security issues in sid high

There are 4 open security issues in sid.

4 important issues:
  • CVE-2026-38819: Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
  • CVE-2026-38820: openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
  • CVE-2026-38821: A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
  • CVE-2026-38822: In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.
Created: 2026-08-28 Last update: 2026-09-04 22:01
4 security issues in forky high

There are 4 open security issues in forky.

4 important issues:
  • CVE-2026-38819: Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
  • CVE-2026-38820: openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
  • CVE-2026-38821: A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
  • CVE-2026-38822: In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.
Created: 2026-08-28 Last update: 2026-09-04 22:01
1 bug tagged patch in the BTS normal
The BTS contains patches fixing 1 bug, consider including or untagging them.
Created: 2026-09-02 Last update: 2026-09-13 07:00
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • opennds-daemon-common could be marked Multi-Arch: foreign
Created: 2022-05-17 Last update: 2026-09-13 05:00
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2025-05-05 Last update: 2025-05-05 10:31
4 low-priority security issues in trixie low

There are 4 open security issues in trixie.

4 issues left for the package maintainer to handle:
  • CVE-2026-38819: (needs triaging) Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
  • CVE-2026-38820: (needs triaging) openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas query parameter on the /opennds_preauth/ endpoint because of libopennds.sh.
  • CVE-2026-38821: (needs triaging) A heap-based buffer overflow vulnerability exists in openNDS before 11.0.0 that allows an unauthenticated attacker on the captive portal network to crash the openNDS daemon (denial of service) and potentially achieve remote code execution. This is in http_microhttpd.c.
  • CVE-2026-38822: (needs triaging) In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-08-28 Last update: 2026-09-04 22:01
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.2).
Created: 2025-12-23 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2025-05-15] opennds 10.3.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-04] Accepted opennds 10.3.1+dfsg-1 (source) into unstable (Mike Gabriel)
  • [2024-10-26] opennds 10.3.0+dfsg-0.1 MIGRATED to testing (Debian testing watch)
  • [2024-10-20] Accepted opennds 10.3.0+dfsg-0.1 (source) into unstable (Chris Hofstaedtler) (signed by: Christian Hofstaedtler)
  • [2024-08-23] opennds REMOVED from testing (Debian testing watch)
  • [2024-01-25] opennds 10.2.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-20] Accepted opennds 10.2.0+dfsg-1 (source) into unstable (Mike Gabriel)
  • [2023-02-12] opennds 9.10.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-02-06] Accepted opennds 9.10.0-1 (source) into unstable (Mike Gabriel)
  • [2022-06-07] Accepted opennds 9.7.0-3~bpo11+1 (source all amd64) into bullseye-backports, bullseye-backports (Debian FTP Masters) (signed by: Mike Gabriel)
  • [2022-05-24] opennds 9.7.0-3 MIGRATED to testing (Debian testing watch)
  • [2022-05-18] Accepted opennds 9.7.0-3 (source) into unstable (Mike Gabriel)
  • [2022-05-18] Accepted opennds 9.7.0-2 (source) into unstable (Mike Gabriel)
  • [2022-05-16] Accepted opennds 9.7.0-1 (source all amd64) into unstable, unstable (Debian FTP Masters) (signed by: Mike Gabriel)
bugs [bug history graph]
  • all: 5
  • RC: 1
  • I&N: 4
  • M&W: 0
  • F&P: 0
  • patch: 1
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 10.3.1+dfsg-1build1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing