CVE-2021-43174
published 2021-11-09CVE-2021-43174: NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.17%
64.2th percentile
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | cfrpki | < cfrpki 1.4.0-1 (bookworm) | cfrpki 1.4.0-1 (bookworm) |
| debian | debian_linux | — | — |
| nlnet_labs | routinator | >= 0.9.0 < 0.10.2 | 0.10.2 |
| nlnet_labs | routinator | unspecified – 0.10.1 | — |
| nlnetlabs | routinator | >= 0.9.0 < 0.10.2 | 0.10.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Memory exhaustion in routinator
ghsa·2021-11-11
CVE-2021-43174 [HIGH] CWE-787 Memory exhaustion in routinator
Memory exhaustion in routinator
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.
OSV
Memory exhaustion in routinator
osv·2021-11-11
CVE-2021-43174 [HIGH] Memory exhaustion in routinator
Memory exhaustion in routinator
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.
OSV
CVE-2021-43174: NLnet Labs Routinator versions 0
osv·2021-11-09·CVSS 7.5
CVE-2021-43174 [HIGH] CVE-2021-43174: NLnet Labs Routinator versions 0
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.
Debian
CVE-2021-43174: cfrpki - NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzi...
vendor_debian·2021·CVSS 7.5
CVE-2021-43174 [HIGH] CVE-2021-43174: cfrpki - NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzi...
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.
Scope: local
bookworm: resolved (fixed in 1.4.0-1)
bullseye: resolved (fixed in 1.4.2-1~deb11u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-09
Published