0.12.2 ‘Brutti, sporchi e cattivi’
Bug Fixes
- Fixed various decoding issues that could lead to a panic when processing invalid RPKI objects. (#891, via bcder release 0.7.3. Found by Haya Shulman, Donika Mirdita and Niklas Vogel. Assigned CVE-2023-39915)
- Check the request URI when generating a path for storing a copy of a RRDP response with the
rrdp-keep-responses
option to avoid path traversal. (#892. Found by Haya Shulman, Donika Mirdita and Niklas Vogel. Assigned CVE-2023-39916.)