UBUNTU-CVE-2021-3909
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-3909
Summary:
Details: OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.
References: https://ubuntu.com/security/CVE-2021-3909, https://github.com/cloudflare/cfrpki/security/advisories/GHSA-8cvr-4rrf-f244, https://github.com/cloudflare/cfrpki/commit/71ac74e691dc791731f90b72710975414ecec1eb, https://github.com/cloudflare/cfrpki/commit/dbc038f83197edc1f3360ab35af193a1557063c6, https://www.cve.org/CVERecord?id=CVE-2021-3909
Affected packages
Package
Name: cfrpki
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
