| |
Vulnerability CVE-2020-26265
Published: 2020-12-11
Description: |
Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. In Geth from version 1.9.4 and before version 1.9.20 a consensus-vulnerability could cause a chain split, where vulnerable versions refuse to accept the canonical chain. The fix was included in the Paragade release version 1.9.20. No individual workaround patches have been made -- all users are recommended to upgrade to a newer version. |
Type:
CWE-682 (Incorrect Calculation)
CVSS2 => (AV:N/AC:M/Au:S/C:N/I:P/A:N)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
3.5/10 |
2.9/10 |
6.8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
None |
Partial |
None |
References: |
https://github.com/ethereum/go-ethereum/releases/tag/v1.9.20
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-xw37-57qp-9mm4
|
|
|
closedb();
?>
Copyright 2024, cxsecurity.com
|
|
|