CVE-2021-43174
Last modified
CVE-2021-43174 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
NLnet Labs Routinator versions 0.9.0 up to and including 0.10.1, support the gzip transfer encoding when querying RRDP repositories. This encoding can be used by an RRDP repository to cause an out-of-memory crash in these versions of Routinator. RRDP uses XML which allows arbitrary amounts of white space in the encoded data. The gzip scheme compresses such white space extremely well, leading to very small compressed files that become huge when being decompressed for further processing, big enough that Routinator runs out of memory when parsing input data waiting for the next XML element.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Routinator | >= 0.9.0, < 0.10.2 |
| Debian | Debian Linux | 11.0 |
References
- https://www.debian.org/security/2022/dsa-5041Third Party Advisory
- https://www.debian.org/security/2022/dsa-5041Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43174?
How severe is CVE-2021-43174?
How do I fix CVE-2021-43174?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43163A Remote Code Execution (RCE) vulnerability exists in Ruijie…9.8
- CVE-2021-43164A Remote Code Execution (RCE) vulnerability exists in Ruijie…8.8
- CVE-2021-4317Use after free in ANGLE in Google Chrome prior to 96.0.4664.…8.8
- CVE-2021-43171Improper verification of applications' cryptographic signatu…6.5
- CVE-2021-43172NLnet Labs Routinator prior to 0.10.2 happily processes a ch…7.5
- CVE-2021-43173In NLnet Labs Routinator prior to 0.10.2, a validation run c…7.5
- CVE-2021-43175The GOautodial API prior to commit 3c3a979 made on October 1…7.5
- CVE-2021-43176The GOautodial API prior to commit 3c3a979 made on October 1…8.8
- CVE-2021-43177As a result of an incomplete fix for CVE-2015-7225, in versi…5.3
- CVE-2021-43178Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-43179Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-4318Object corruption in Blink in Google Chrome prior to 94.0.46…8.8
Are you affected by CVE-2021-43174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
