Description
ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a “code: Buffer.from(my_code, ‘hex’)” attribute.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.4.0
References
Could your website be exposed too?
SmartScanner can check your website for Denial of Service in ethereumjs-vm and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Regular Expression Denial of Service in highcharts - highcharts - CVE-2018-20801
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- Denial of Service in protobufjs - protobufjs - CVE-2018-3738
- Regular Expression Denial of Service (ReDoS) in braces - CVE-2018-1109
You might also like:
See something that needs correcting? Let us knowUpdated January 09, 2023


