Description
OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to 1.4
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5033-1 | fort-validator security update |
Debian DSA |
DSA-5041-1 | cfrpki security update |
EUVD |
EUVD-2021-2322 | OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive. |
Github GHSA |
GHSA-8cvr-4rrf-f244 | Infinite open connection causes OctoRPKI to hang forever |
References
History
No history.
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2024-09-16T23:06:15.208Z
Reserved: 2021-10-26T00:00:00.000Z
Link: CVE-2021-3909
No data.
Status : Modified
Published: 2021-11-11T22:15:07.923
Modified: 2024-11-21T06:22:45.307
Link: CVE-2021-3909
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA