UBUNTU-CVE-2022-3616

Source
https://ubuntu.com/security/CVE-2022-3616
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-3616.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2022-3616
Related
Published
2022-10-28T07:15:00Z
Modified
2025-01-13T10:23:21Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.

References

Affected packages

Ubuntu:22.04:LTS / cfrpki

Package

Name
cfrpki
Purl
pkg:deb/ubuntu/cfrpki@1.4.2-1ubuntu0.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.2.2-1
1.3.0-1
1.4.0-1
1.4.2-1
1.4.2-1ubuntu0.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}