Nlnetlabs

Routinator

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 22.01.2025 16:15:29
  • Zuletzt bearbeitet 22.01.2025 16:15:29

The initial code parsing the manifest did not check the content of the file names yet later code assumed that it was checked and panicked when encountering illegal characters, resulting in a crash of Routinator.

  • EPSS 0.2%
  • Veröffentlicht 26.02.2024 16:27:52
  • Zuletzt bearbeitet 27.02.2025 03:05:58

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

  • EPSS 0.35%
  • Veröffentlicht 13.09.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:16:01

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

  • EPSS 0.15%
  • Veröffentlicht 13.09.2023 15:15:07
  • Zuletzt bearbeitet 03.10.2025 10:15:33

NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 as well as 0.14.0 up to and including 0.14.2 contains a possible path traversal vulnerability in the optional, off-by-default keep-rrdp-responses feature that allows users to store the content o...

  • EPSS 0.34%
  • Veröffentlicht 13.09.2022 16:15:09
  • Zuletzt bearbeitet 21.11.2024 07:18:40

In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t correctly base 64 encoded is treated as a fatal error and causes Routinator to exit. Worst case impact of ...

  • EPSS 0.54%
  • Veröffentlicht 09.11.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:46

NLnet Labs Routinator prior to 0.10.2 happily processes a chain of RRDP repositories of infinite length causing it to never finish a validation run. In RPKI, a CA can choose the RRDP repository it wishes to publish its data in. By continuously genera...

  • EPSS 0.44%
  • Veröffentlicht 09.11.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:46

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routina...

  • EPSS 0.72%
  • Veröffentlicht 09.11.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 06:28:46

NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP...

  • EPSS 0.35%
  • Veröffentlicht 21.09.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:26:21

NLnet Labs Routinator prior to 0.10.0 produces invalid RTR payload if an RPKI CA uses too large values in the max-length parameter in a ROA. This will lead to RTR clients such as routers to reject the RPKI data set, effectively disabling Route Origin...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 05.08.2020 22:15:12
  • Zuletzt bearbeitet 21.11.2024 05:07:57

An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Author...