NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
References
Link | Resource |
---|---|
https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt | Vendor Advisory |
https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt | Vendor Advisory |
Configurations
History
21 Nov 2024, 08:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt - Vendor Advisory |
11 Sep 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-13 15:15
Updated : 2024-11-21 08:16
NVD link : CVE-2023-39915
Mitre link : CVE-2023-39915
CVE.ORG link : CVE-2023-39915
JSON object : View
Products Affected
nlnetlabs
- routinator
CWE
CWE-232
Improper Handling of Undefined Values
CWE-240Improper Handling of Inconsistent Structural Elements
NVD-CWE-noinfo