← voltar
CVE-2024-32972

go-ethereum denial of service via malicious p2p message

CVSS 7.5 HIGHEPSS 0.8%CWE-400
go-ethereum (geth) is a golang execution layer implementation of the Ethereum protocol. Prior to 1.13.15, a vulnerable node can be made to consume very large amounts of memory when handling specially crafted p2p messages sent from an attacker node. The fix has been included in geth version `1.13.15` and onwards.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
ethereum · go-ethereum

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →