NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
History

Fri, 13 Sep 2024 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-228

Wed, 11 Sep 2024 15:45:00 +0000

Type Values Removed Values Added
Description NLnet Labs’ Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914. NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
Weaknesses CWE-232
CWE-240

cve-icon MITRE

Status: PUBLISHED

Assigner: NLnet Labs

Published: 2023-09-13T14:20:59.967Z

Updated: 2024-09-12T13:22:03.133Z

Reserved: 2023-08-07T11:55:17.843Z

Link: CVE-2023-39915

cve-icon Vulnrichment

Updated: 2024-08-02T18:18:10.006Z

cve-icon NVD

Status : Modified

Published: 2023-09-13T15:15:07.763

Modified: 2024-11-21T08:16:01.923

Link: CVE-2023-39915

cve-icon Redhat

No data.