HomeFreeBSD

net/routinator: Update to 0.12.2

Description

net/routinator: Update to 0.12.2

Routinator 0.12.2 ‘Brutti, sporchi e cattivi’

This release fixes two issues in Routinator that can be exploited
remotely by rogue RPKI CAs and repositories. We therefore advise all
users of Routinator to upgrade to this release at their earliest
convenience.

The first issue, CVE-2022-39915, can lead to Routinator crashing when
trying to decode certain illegal RPKI objects.

The second issue, CVE-2022-39916, only affects users that have the
rrdp-keep-responses option enabled which allows storing all received
RRDP responses on disk. Because the file name for these responses is
derived from the URI and the path wasn’t checked properly, a RRDP URI
could be constructed that results in the response stored outside the
directory, possibly overwriting existing files.

We would like to thank Haya Shulman, Donika Mirdita and Niklas Vogel
for discovering and reporting these issues.

Changelog: https://nlnetlabs.nl/news/2023/Sep/13/routinator-0.12.2-released/

PR: 273826
MFH: 2023Q3

Details

Provenance
Jaap Akkerhuis <jaap@NLnetLabs.nl>Authored on Sep 15 2023, 12:04 PM
fuzCommitted on Sep 17 2023, 3:23 PM
Parents
R11:13279411a21e: textproc/wikiman: update to 2.13.2
Branches
Unknown
Tags
Unknown