Описание
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.
A flaw was found in Routinator. A remote attacker could exploit this vulnerability by providing a specially crafted Document Type Definition (DTD) file through the Relying Party RPKI Data Protocol (RRDP). This could lead to Routinator crashing, resulting in a Denial of Service (DoS) for the affected system.
Отчет
This is an Important denial of service flaw in Routinator, which could be triggered remotely by an unauthenticated attacker providing a specially crafted Document Type Definition (DTD) file via the Relying Party RPKI Data Protocol (RRDP). Successful exploitation would lead to the Routinator service crashing, impacting the availability of RPKI validation services.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.
When Routinator encounters a file via RRDP using a specifically crafte ...
Routinator crashes when encountering maliciously crafted RRDP XML files
EPSS
7.5 High
CVSS3