Description
ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a “code: Buffer.from(my_code, ‘hex’)” attribute.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.4.0
References
Related Issues
- Regular Expression Denial of Service in highcharts - highcharts - CVE-2018-20801
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- Denial of Service in protobufjs - protobufjs - CVE-2018-3738
- Regular Expression Denial of Service (ReDoS) in braces - CVE-2018-1109
You might also like:
- Tags:
- npm
- ethereumjs-vm
Anything's wrong? Let us know Last updated on January 09, 2023


