Skip to content

Bitcoin Inventory Out-of-Memory Denial-of-Service Attack (CVE-2018-17145)

High
braydonf published GHSA-hx3r-jv9q-85jw Sep 10, 2020

Package

No package listed

Affected versions

<= v1.0.0-pre

Patched versions

>= 1.0.2

Description

There was an easily exploitable uncontrolled memory resource consumption denial-of-service vulnerability that existed in the peer-to-peer network code of three implementations of Bitcoin and several alternative chains.

For more details please see:
https://invdos.net/

For the paper:
https://invdos.net/paper/CVE-2018-17145.pdf

Severity

High

CVE ID

CVE-2018-17145

Weaknesses

No CWEs