CVE-2017-14457
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read leading to memory disclosure or denial of service. An attacker can create/send malicious a smart contract to trigger this vulnerability.
Existe una vulnerabilidad explotable de fuga de información/denegación de servicio (DoS) en el manipulador opcode "create2" de libevm (Ethereum Virtual Machine) en CPP-Ethereum. Un código smart contract especialmente manipulado puede permitir una lectura fuera de límites, que conduce a una revelación de memoria o a una denegación de servicio (DoS). Un atacante puede crear/enviar un smart contract malicioso para provocar esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-09-13 CVE Reserved
- 2018-01-19 CVE Published
- 2023-11-29 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/102475 | Third Party Advisory | |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0503 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ethereum Search vendor "Ethereum" | Ethereum Virtual Machine Search vendor "Ethereum" for product "Ethereum Virtual Machine" | - | - |
Affected
|