ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute.
References
Link | Resource |
---|---|
https://github.com/ethereumjs/ethereumjs-vm/issues/386 | Exploit Third Party Advisory |
Configurations
Information
Published : 2018-11-11 18:29
Updated : 2020-07-14 13:12
NVD link : CVE-2018-19183
Mitre link : CVE-2018-19183
JSON object : View
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer
Products Affected
ethereumjs-vm_project
- ethereumjs-vm