First published: Wed Sep 13 2023(Updated: )
NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
Credit: sep@nlnetlabs.nl sep@nlnetlabs.nl
Affected Software | Affected Version | How to fix |
---|---|---|
NLnet Labs Routinator | <0.12.2 |
This issue is fixed in 0.12.2 and all later versions.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for NLnet Labs’ Routinator is CVE-2023-39915.
The severity of CVE-2023-39915 is high with a severity value of 7.5.
NLnet Labs’ Routinator up to and including version 0.12.1 is affected by CVE-2023-39915.
CVE-2023-39915 is caused by insufficient input checking in the bcder library.
You can find more information about CVE-2023-39915 at the following link: [link](https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt).