Vulnerability CVE-2021-41173


Published: 2021-10-26

Description:
Go Ethereum is the official Golang implementation of the Ethereum protocol. Prior to version 1.10.9, a vulnerable node is susceptible to crash when processing a maliciously crafted message from a peer. Version v1.10.9 contains patches to the vulnerability. There are no known workarounds aside from upgrading.

Type:

NVD-CWE-noinfo

CVSS2 => (AV:N/AC:M/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
3.5/10
2.9/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Ethereum -> Go ethereum 

 References:
https://github.com/ethereum/go-ethereum/pull/23801
https://github.com/ethereum/go-ethereum/releases/tag/v1.10.9
https://github.com/ethereum/go-ethereum/security/advisories/GHSA-59hh-656j-3p7v
https://github.com/ethereum/go-ethereum/commit/e40b37718326b8b4873b3b00a0db2e6c6d9ea738

Copyright 2024, cxsecurity.com

 

Back to Top