Nicmx

Fort-validator

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.39%
  • Veröffentlicht 22.12.2024 23:15:06
  • Zuletzt bearbeitet 22.04.2025 15:54:43

An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (an...

  • EPSS 0.37%
  • Veröffentlicht 18.12.2024 05:15:09
  • Zuletzt bearbeitet 22.04.2025 15:35:05

A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest should be pr...

  • EPSS 0.06%
  • Veröffentlicht 24.08.2024 23:15:04
  • Zuletzt bearbeitet 03.11.2025 21:16:19

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER ...

  • EPSS 0.19%
  • Veröffentlicht 24.08.2024 23:15:04
  • Zuletzt bearbeitet 03.11.2025 21:16:20

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses the set's elements without s...

  • EPSS 0.27%
  • Veröffentlicht 24.08.2024 23:15:04
  • Zuletzt bearbeitet 03.11.2025 21:16:20

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort ...

  • EPSS 0.22%
  • Veröffentlicht 24.08.2024 23:15:04
  • Zuletzt bearbeitet 03.11.2025 21:16:20

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizin...