First published: Thu Nov 11 2021(Updated: )
OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/cfrpki | 1.4.2-1~deb11u1 1.4.4-1 1.5.10-2 | |
Cloudflare Octorpki | <1.3.0 | |
Debian Debian Linux | =11.0 |
Upgrade to 1.4
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3910 is a vulnerability that affects OctoRPKI and Debian Linux, allowing a specially crafted repository to cause a crash by returning an invalid ROA.
CVE-2021-3910 has a severity of 7.5 (high).
OctoRPKI versions 1.3.0 and earlier, as well as Debian Linux 11.0, are affected by CVE-2021-3910.
To fix CVE-2021-3910, update OctoRPKI to version 1.4.2-1~deb11u1, 1.4.4-1, or 1.5.10-2, or update Debian Linux to the latest version.
For more information about CVE-2021-3910, you can refer to the following sources: [GitHub Advisory](https://github.com/cloudflare/cfrpki/security/advisories/GHSA-5mxh-2qfv-4g7j), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2021-3910), [Debian Security Advisory](https://www.debian.org/security/2022/dsa-5041)