GHSA-w6ww-fmfx-2x22
Dashboard / Vulnerabilities / GHSA-w6ww-fmfx-2x22
GHSA-w6ww-fmfx-2x22
Summary: Misconfigured IP address field in ROA leads to OctoRPKI crash
Details: If the ROA that a repository returns contains too many bits for the IP address then OctoRPKI will crash. ## Patches ## For more information If you have any questions or comments about this advisory email us at [email protected]
References: https://github.com/cloudflare/cfrpki/security/advisories/GHSA-w6ww-fmfx-2x22, https://nvd.nist.gov/vuln/detail/CVE-2021-3911, https://github.com/cloudflare/cfrpki/commit/2882307febd66801de97b2a2ce4d93fe58132005, https://github.com/cloudflare/cfrpki, https://pkg.go.dev/vuln/GO-2022-0252, https://www.debian.org/security/2022/dsa-5041
Affected packages
Package
Name: github.com/cloudflare/cfrpki
Purl: pkg:golang/github.com/cloudflare/cfrpki
Affected ranges
Type: SEMVER
Events:
