Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v592-xf75-856p

Опубликовано: 29 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Erroneous Proof of Work calculation in geth

Impact

An ethash mining DAG generation flaw in Geth could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected.

Patches

This issue is also fixed as of 1.9.24. Thanks to @slavikus for bringing the issue to our attention and writing the fix.

Workarounds

This PR implements a patch: https://github.com/ethereum/go-ethereum/pull/21793

References

https://blog.ethereum.org/2020/11/12/geth_security_release/

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/ethereum/go-ethereum

go
Затронутые версииВерсия исправления

< 1.9.24

1.9.24

EPSS

Процентиль: 59%
0.00386
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-682

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

Go Ethereum, or "Geth", is the official Golang implementation of the Ethereum protocol. An ethash mining DAG generation flaw in Geth before version 1.9.24 could cause miners to erroneously calculate PoW in an upcoming epoch (estimated early January, 2021). This happened on the ETC chain on 2020-11-06. This issue is relevant only for miners, non-mining nodes are unaffected. This issue is fixed as of 1.9.24

CVSS3: 5.3
debian
около 5 лет назад

Go Ethereum, or "Geth", is the official Golang implementation of the E ...

EPSS

Процентиль: 59%
0.00386
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-682