PT-2022-23238 · Octorpki+1 · Octorpki+1

Mskowroncf

·

Published

2022-10-28

·

Updated

2024-08-21

·

CVE-2022-3616

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions OctoRPKI versions prior to 1.4.4
Description Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter, causing the program to crash and preventing it from finishing the validation, resulting in a denial of service. This issue was discovered and reported by Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE.
Recommendations For versions prior to 1.4.4, update to version 1.4.4 to resolve the issue. As a temporary workaround, consider restricting the length of CA chains to prevent exceeding the max iterations parameter until a patch is applied.

Fix

DoS

Improper Check for Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3616
GHSA-PMW9-567P-68PC
GO-2022-1089

Affected Products

Debian
Octorpki