CVE-2021-3910

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
11/11/2021
Last modified:
04/04/2022

Description

OctoRPKI crashes when encountering a repository that returns an invalid ROA (just an encoded NUL (\0) character).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudflare:octorpki:*:*:*:*:*:*:*:* 1.3.0 (excluding)
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*