CVE-2024-45237: Buffer Overflow
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a 2-byte buffer without properly sanitizing its length, leading to a buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45237?
CVE-2024-45237 is considered a high-severity vulnerability due to its potential impact on resource certificate integrity.
How do I fix CVE-2024-45237?
To fix CVE-2024-45237, upgrade Fort to version 1.6.3 or later.
What software is affected by CVE-2024-45237?
CVE-2024-45237 affects NICMx FORT Validator versions prior to 1.6.3.
What kind of vulnerability is CVE-2024-45237?
CVE-2024-45237 is a buffer overflow vulnerability caused by improperly handling a Key Usage extension.
Can CVE-2024-45237 lead to exploitation?
Yes, CVE-2024-45237 can potentially be exploited by a malicious RPKI repository to execute arbitrary code.