Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2024-48943

Medium priority
Needs evaluation

A malicious RPKI rsync repository can prevent Fort from finishing its validation run by drip-feeding its content.

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-56375

Medium priority
Needs evaluation

An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Manifest RPKI object containing an empty fileList....

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-56170

Medium priority
Needs evaluation

A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-56169

Medium priority
Needs evaluation

A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. This can be employed as a fallback in case a new...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45239

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a null eContent field. Fort dereferences the...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45238

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45237

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45236

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45235

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing an Authority Key Identifier extension that lacks...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-45234

Medium priority
Needs evaluation

An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing a signedAttrs encoded in non-canonical form. This...

1 affected package

fort-validator

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
fort-validator Needs evaluation Needs evaluation Needs evaluation
Show less packages