NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt |
|
History
Fri, 13 Sep 2024 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 11 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-228 |
Wed, 11 Sep 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NLnet Labs’ Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914. | NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914. |
| Weaknesses | CWE-232 CWE-240 |
Status: PUBLISHED
Assigner: NLnet Labs
Published: 2023-09-13T14:20:59.967Z
Updated: 2024-09-12T13:22:03.133Z
Reserved: 2023-08-07T11:55:17.843Z
Link: CVE-2023-39915
Updated: 2024-08-02T18:18:10.006Z
Status : Modified
Published: 2023-09-13T15:15:07.763
Modified: 2024-11-21T08:16:01.923
Link: CVE-2023-39915
No data.
ReportizFlow