CVE-2024-56375
- EPSS 0.23%
- Veröffentlicht 22.12.2024 23:15:06
- Zuletzt bearbeitet 22.04.2025 15:54:43
An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList. Fort dereferences (an...
CVE-2024-56170
- EPSS 0.09%
- Veröffentlicht 18.12.2024 05:15:09
- Zuletzt bearbeitet 22.04.2025 15:35:05
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest should be pr...
CVE-2024-45234
- EPSS 0.07%
- Veröffentlicht 24.08.2024 23:15:04
- Zuletzt bearbeitet 25.03.2025 19:15:45
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This bypasses Fort's BER ...
CVE-2024-45236
- EPSS 0.23%
- Veröffentlicht 24.08.2024 23:15:04
- Zuletzt bearbeitet 26.03.2025 20:15:20
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses the set's elements without s...
CVE-2024-45237
- EPSS 0.24%
- Veröffentlicht 24.08.2024 23:15:04
- Zuletzt bearbeitet 27.08.2024 15:48:34
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort ...
CVE-2024-45239
- EPSS 0.27%
- Veröffentlicht 24.08.2024 23:15:04
- Zuletzt bearbeitet 19.03.2025 14:15:36
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the pointer without sanitizin...