{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-39915","assignerOrgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","state":"PUBLISHED","assignerShortName":"NLnet Labs","dateReserved":"2023-08-07T11:55:17.843Z","datePublished":"2023-09-13T14:20:59.967Z","dateUpdated":"2024-09-12T13:22:03.133Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Routinator","vendor":"NLnet Labs","versions":[{"lessThan":"0.12.2","status":"affected","version":"*","versionType":"semver"},{"lessThan":"*","status":"unaffected","version":"0.12.2","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Haya Shulman"},{"lang":"en","type":"finder","value":"Donika Mirdita"},{"lang":"en","type":"finder","value":"Niklas Vogel"}],"datePublic":"2023-09-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914."}],"metrics":[{"cvssV3_1":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-232","description":"CWE-232: Improper Handling of Undefined Values","lang":"en","type":"CWE"},{"cweId":"CWE-240","description":"CWE-240: Improper Handling of Inconsistent Structural Elements","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","shortName":"NLnet Labs","dateUpdated":"2024-09-11T15:36:54.043Z"},"references":[{"tags":["vendor-advisory"],"url":"https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt"}],"solutions":[{"lang":"en","value":"This issue is fixed in 0.12.2 and all later versions."}],"timeline":[{"lang":"en","time":"2023-07-19T18:00:00.000Z","value":"Issue reported by Haya Shulman"},{"lang":"en","time":"2023-09-13T14:00:00.000Z","value":"Fixes released"}],"title":"Crashes on parsing certain invalid RPKI objects"},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T18:18:10.006Z"},"title":"CVE Program Container","references":[{"url":"https://nlnetlabs.nl/downloads/routinator/CVE-2023-39915.txt","tags":["vendor-advisory","x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-12T13:21:49.530155Z","id":"CVE-2023-39915","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-12T13:22:03.133Z"}}]}}