Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-26895

Опубликовано: 21 окт. 2020
Источник: debian
EPSS Низкий

Описание

Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or payment-sender). The impact is a loss of funds in certain situations.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
lnditppackage

EPSS

Процентиль: 35%
0.00148
Низкий

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

Prior to 0.10.0-beta, LND (Lightning Network Daemon) would have accepted a counterparty high-S signature and broadcast tx-relay invalid local commitment/HTLC transactions. This can be exploited by any peer with an open channel regardless of the victim situation (e.g., routing node, payment-receiver, or payment-sender). The impact is a loss of funds in certain situations.

EPSS

Процентиль: 35%
0.00148
Низкий