CVE-2023-39915

Source
https://cve.org/CVERecord?id=CVE-2023-39915
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39915.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-39915
Published
2023-09-13T15:15:07.763Z
Modified
2026-04-10T04:59:35.528613Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

References

Affected packages

Git / github.com/nlnetlabs/routinator

Affected ranges

Type
GIT
Repo
https://github.com/nlnetlabs/routinator
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.12.2"
        }
    ]
}

Affected versions

0.*
0.9.0
v0.*
v0.1.0
v0.1.1
v0.1.2
v0.10.0
v0.10.0-rc1
v0.10.0-rc2
v0.10.0-rc3
v0.10.1
v0.10.1-rc1
v0.10.1-rc2
v0.10.1-rc3
v0.10.2
v0.11.0
v0.11.0-rc1
v0.11.0-rc2
v0.11.1
v0.11.1-rc1
v0.11.2
v0.12.0
v0.12.0-rc1
v0.12.1
v0.12.1-rc1
v0.12.1-rc2
v0.2.0
v0.2.1
v0.3.0
v0.3.1
v0.3.2
v0.3.3
v0.4.0
v0.5.0
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.7.0
v0.7.0-rc1
v0.7.0-rc2
v0.7.0-rc3
v0.7.1
v0.7.1-rc1
v0.7.1-rc2
v0.8.0
v0.8.0-rc1
v0.8.0-rc2
v0.8.1
v0.8.1-rc1
v0.8.2
v0.8.2-rc1
v0.9.0
v0.9.0-rc1
v0.9.0-rc2
v0.9.0-rc3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-39915.json"