Description
OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Upgrade to 1.4
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-5041-1 | cfrpki security update |
EUVD |
EUVD-2021-2346 | OctoRPKI tries to load the entire contents of a repository in memory, and in the case of a GZIP bomb, unzip it in memory, making it possible to create a repository that makes OctoRPKI run out of memory (and thus crash). |
Github GHSA |
GHSA-g9wh-3vrx-r7hg | OctoRPKI crashes when processing GZIP bomb returned via malicious repository |
References
History
No history.
Status: PUBLISHED
Assigner: cloudflare
Published:
Updated: 2024-09-16T23:41:30.954Z
Reserved: 2021-10-26T00:00:00.000Z
Link: CVE-2021-3912
No data.
Status : Modified
Published: 2021-11-11T22:15:08.077
Modified: 2024-11-21T06:22:45.710
Link: CVE-2021-3912
No data.
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Github GHSA