Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-27611

Опубликовано: 30 апр. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.

A flaw was found in base-x. This vulnerability allows attackers to generate addresses that appear legitimate, tricking users into sending money to them instead of the intended ones. The problem arises from the way base-x compresses leading zeros in addresses via manipulation of the base encoding mechanism.

Отчет

This vulnerability in base-x is Important because it affects the encoding and decoding of addresses in blockchain transactions. The flaw arises from mishandling of leading zero compression, enabling attackers to craft malicious encodings that deceive systems or users into misdirecting funds. As blockchain transactions are final and cannot be reversed, even a single instance of this exploit can result in permanent financial loss, making this a serious security concern beyond a Moderate issue.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packorg.jboss.hal-hal-parentNot affected
Red Hat JBoss Enterprise Application Platform 8.0.8org.jboss.hal-hal-parentFixedRHSA-2025:1045907.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-activemq-artemisFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-apache-commons-beanutilsFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-apache-cxfFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-apache-mime4jFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-eap-product-conf-parentFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-elytron-webFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-fastinfosetFixedRHSA-2025:1045207.07.2025
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8eap8-hal-consoleFixedRHSA-2025:1045207.07.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1007
https://bugzilla.redhat.com/show_bug.cgi?id=2363176base-x: base-x homograph attack allows Unicode lookalike characters to bypass validation.

EPSS

Процентиль: 26%
0.00085
Низкий

7.5 High

CVSS3

Связанные уязвимости

nvd
5 месяцев назад

base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.

github
5 месяцев назад

Homograph attack allows Unicode lookalike characters to bypass validation.

EPSS

Процентиль: 26%
0.00085
Низкий

7.5 High

CVSS3