HIGH🇵🇱 Wersja polska

CVE-2023-39915

CVSS 7.5v3.1pub. 2023-09-13upd. 2024-11-21

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Nlnetlabs Routinator

    APP
    Nlnetlabs
    < 0.12.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2023-39916CRITICAL9.3PL ✓same product

Path traversal w NLnet Labs Routinator — zapis odpowiedzi RRDP poza dozwolonym katalogiem

CVE-2026-49233HIGH8.3same product

Routinator does not properly check the module component of rsync URIs, which are used to create the file syste...

CVE-2026-49234HIGH8.2same product

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endp...

CVE-2026-49235HIGH8.7same product

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator c...

CVE-2024-1622HIGH7.5same product

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the ...