Описание
base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.
A flaw was found in base-x. This vulnerability allows attackers to generate addresses that appear legitimate, tricking users into sending money to them instead of the intended ones. The problem arises from the way base-x compresses leading zeros in addresses via manipulation of the base encoding mechanism.
Отчет
This vulnerability in base-x is Important because it affects the encoding and decoding of addresses in blockchain transactions. The flaw arises from mishandling of leading zero compression, enabling attackers to craft malicious encodings that deceive systems or users into misdirecting funds. As blockchain transactions are final and cannot be reversed, even a single instance of this exploit can result in permanent financial loss, making this a serious security concern beyond a Moderate issue.
Меры по смягчению последствий
No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat JBoss Enterprise Application Platform Expansion Pack | org.jboss.hal-hal-parent | Not affected | ||
Red Hat JBoss Enterprise Application Platform 8.0.8 | org.jboss.hal-hal-parent | Fixed | RHSA-2025:10459 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-activemq-artemis | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-apache-commons-beanutils | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-apache-cxf | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-apache-mime4j | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-eap-product-conf-parent | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-elytron-web | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-fastinfoset | Fixed | RHSA-2025:10452 | 07.07.2025 |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-hal-console | Fixed | RHSA-2025:10452 | 07.07.2025 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
base-x is a base encoder and decoder of any given alphabet using bitcoin style leading zero compression. Versions 4.0.0, 5.0.0, and all prior to 3.0.11, are vulnerable to attackers potentially deceiving users into sending funds to an unintended address. This issue has been patched in versions 3.0.11, 4.0.1, and 5.0.1.
Homograph attack allows Unicode lookalike characters to bypass validation.
EPSS
7.5 High
CVSS3