NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
References
Link | Resource |
---|---|
https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt | Vendor Advisory |
Configurations
History
11 Sep 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-232 CWE-240 |
|
Summary | (en) NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914. |
15 Sep 2023, 19:04
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:nlnetlabs:routinator:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
First Time |
Nlnetlabs
Nlnetlabs routinator |
13 Sep 2023, 16:34
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-09-13 15:15
Updated : 2024-09-11 16:15
NVD link : CVE-2023-39915
Mitre link : CVE-2023-39915
CVE.ORG link : CVE-2023-39915
JSON object : View
Products Affected
nlnetlabs
- routinator
CWE
NVD-CWE-noinfo
CWE-232
Improper Handling of Undefined Values
CWE-240Improper Handling of Inconsistent Structural Elements