Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-43173

Опубликовано: 09 нояб. 2021
Источник: ubuntu
Приоритет: medium
CVSS2: 5
CVSS3: 7.5

Описание

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individual read or write operations rather than the complete request. Thus, if an RRDP repository sends a little bit of data before that time-out expired, it can continuously extend the time it takes for the request to finish. Since validation will only continue once the update of an RRDP repository has concluded, this delay will cause validation to stall, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.

РелизСтатусПримечание
devel

DNE

esm-apps/jammy

not-affected

1.4.2-1
impish

ignored

end of life
jammy

not-affected

1.4.2-1
kinetic

not-affected

1.4.2-1
lunar

not-affected

1.4.2-1
mantic

not-affected

1.4.2-1
noble

DNE

oracular

DNE

plucky

DNE

Показывать по

РелизСтатусПримечание
devel

not-affected

1.6.6-1build1
esm-apps/focal

needed

esm-apps/jammy

not-affected

1.5.3-1build1
esm-apps/noble

not-affected

1.6.1-1ubuntu0.1~esm2
focal

ignored

end of standard support, was needs-triage
impish

ignored

end of life
jammy

not-affected

1.5.3-1build1
kinetic

ignored

end of life
lunar

ignored

end of life
mantic

ignored

end of life

Показывать по

РелизСтатусПримечание
trusty

ignored

end of standard support
upstream

needs-triage

xenial

ignored

end of standard support

Показывать по

РелизСтатусПримечание
devel

not-affected

7.5-1build1
esm-apps/jammy

not-affected

7.5-1build1
esm-apps/noble

not-affected

7.5-1build1
impish

ignored

end of life
jammy

not-affected

7.5-1build1
kinetic

not-affected

7.5-1build1
lunar

not-affected

7.5-1build1
mantic

not-affected

7.5-1build1
noble

not-affected

7.5-1build1
oracular

not-affected

7.5-1build1

Показывать по

5 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individual read or write operations rather than the complete request. Thus, if an RRDP repository sends a little bit of data before that time-out expired, it can continuously extend the time it takes for the request to finish. Since validation will only continue once the update of an RRDP repository has concluded, this delay will cause validation to stall, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.

CVSS3: 7.5
debian
около 4 лет назад

In NLnet Labs Routinator prior to 0.10.2, a validation run can be dela ...

CVSS3: 7.5
github
больше 3 лет назад

In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individual read or write operations rather than the complete request. Thus, if an RRDP repository sends a little bit of data before that time-out expired, it can continuously extend the time it takes for the request to finish. Since validation will only continue once the update of an RRDP repository has concluded, this delay will cause validation to stall, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.

5 Medium

CVSS2

7.5 High

CVSS3