CVE-2023-39914
published 2023-09-13CVE-2023-39914: NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This…
PriorityP336high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.59%
45.0th percentile
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | rust-bcder | < rust-bcder 0.7.3-1 (trixie) | rust-bcder 0.7.3-1 (trixie) |
| nlnet_labs | routinator | >= * < 0.12.2 | 0.12.2 |
| nlnetlabs | bcder | < 0.7.3 | 0.7.3 |
| nlnetlabs | bcder | >= 0 < 0.7.3 | 0.7.3 |
| nlnetlabs | bcder | >= 0.0.0-0 < 0.7.3 | 0.7.3 |
| nlnetlabs | routinator | < 0.12.2 | 0.12.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2023-39914: rust-bcder - NLnet Labs' bcder library up to and including version 0.7.2 panics while decodin...
vendor_debian·2023·CVSS 7.5
CVE-2023-39914 [HIGH] CVE-2023-39914: rust-bcder - NLnet Labs' bcder library up to and including version 0.7.2 panics while decodin...
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
Scope: local
bookworm: open
trixie: resolved (fixed in 0.7.3-1)
GHSA
BER/CER/DER decoder panics on invalid input
ghsa·2023-09-13
CVE-2023-39914 [HIGH] CWE-228 BER/CER/DER decoder panics on invalid input
BER/CER/DER decoder panics on invalid input
NLnet Labs’ bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
GHSA
GHSA-xhpp-8gq6-3hf5: NLnet Labs’ Routinator up to and including version 0
ghsa_unreviewed·2023-09-13·CVSS 7.5
CVE-2023-39915 [HIGH] CWE-228 GHSA-xhpp-8gq6-3hf5: NLnet Labs’ Routinator up to and including version 0
NLnet Labs’ Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
OSV
BER/CER/DER decoder panics on invalid input
osv·2023-09-13
CVE-2023-39914 [HIGH] BER/CER/DER decoder panics on invalid input
BER/CER/DER decoder panics on invalid input
NLnet Labs’ bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
OSV
BER/CER/DER decoder panics on invalid input
osv·2023-09-13
CVE-2023-39914 BER/CER/DER decoder panics on invalid input
BER/CER/DER decoder panics on invalid input
Due to insufficient checking of input data, decoding certain data sequences
can lead to _bcder_ panicking rather than returning an error. This can affect
both the actual decoding stage as well as accessing content of types that
utilized delayed decoding.
bcder 0.7.3 fixes these issues by more thoroughly checking inputs and
returning errors as expected.
OSV
CVE-2023-39914: NLnet Labs' bcder library up to and including version 0
osv·2023-09-13·CVSS 7.5
CVE-2023-39914 [HIGH] CVE-2023-39914: NLnet Labs' bcder library up to and including version 0
NLnet Labs' bcder library up to and including version 0.7.2 panics while decoding certain invalid input data rather than rejecting the data with an error. This can affect both the actual decoding stage as well as accessing content of types that utilized delayed decoding.
No detection rules found.
No public exploits indexed.
2023-09-13
Published