Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3909

Опубликовано: 11 нояб. 2021
Источник: debian

Описание

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
routinatoritppackage
cfrpkifixed1.4.0-1package
fort-validatorfixed1.5.3-1package
rpki-clientfixed7.5-1package
rpki-clientignoredbullseyepackage

Примечания

  • https://github.com/cloudflare/cfrpki/security/advisories/GHSA-8cvr-4rrf-f244

Связанные уязвимости

CVSS3: 4.4
ubuntu
около 4 лет назад

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

CVSS3: 4.4
nvd
около 4 лет назад

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

CVSS3: 4.4
github
около 4 лет назад

Infinite open connection causes OctoRPKI to hang forever