CVE-2024-45239: Null Pointer Dereference
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45239?
CVE-2024-45239 is classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-45239?
To resolve CVE-2024-45239, upgrade to Fort version 1.6.3 or later that addresses this vulnerability.
What systems are affected by CVE-2024-45239?
CVE-2024-45239 affects Fort Validator versions prior to 1.6.3.
What type of attack does CVE-2024-45239 expose users to?
CVE-2024-45239 exposes users to potential exploitation through malicious RPKI repositories.
Is CVE-2024-45239 a local or remote vulnerability?
CVE-2024-45239 is considered a remote vulnerability, allowing attackers to exploit it over the network.