HomeEthereumSecurity Alert – Geth suffers from a very low probable DoS attack...

Security Alert – Geth suffers from a very low probable DoS attack vector – Update immediately

-


Affected configurations: All Go client versions 

Likelihood: Very low

Severity: High

Details: A bug in Geth (and potentially other clients) may suffer from a DoS attack and allows remote attackers to stall synchronisation process almost indefinitely by supplying a valid, lighter chain. More information will be given out a later time including the report that was submitted through the bug bounty program.

Effects on expected chain reorganisation depth: None

Proposed temporary workaround: None

Remedial action taken by Ethereum: Provision of hotfixes as below:

If you’re using Mist: download the updated binary from the release page

If using the PPA: sudo apt-get update then sudo apt-get upgrade

If using brew: brew update then brew reinstall ethereum

If using a windows binary: download the updated binary from the release page

If you are building from source: git pull followed by make geth (please use the Master branch 94ad694a26ca3f7776ec8240802596755e5d5c0a)



Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

LATEST POSTS

On Settlement Finality | Ethereum Foundation Blog

Special thanks to Tim Swanson for reviewing, and for further discussions on the arguments in his original paper on settlement finality. Recently one of the...

Security Alert – cpp-ethereum keeps accounts unlocked

Affected configurations: cpp-ethereum (eth, AlethZero, ...) version 1.2.0 up to 1.2.5 (fixed in 1.2.6) Note: Neither "geth" nor "Mist" nor the "Ethereum Wallet" (unless...

Go Ethereum’s JIT-EVM | Ethereum Foundation Blog

The Ethereum Virtual machine is kind of different than most other Virtual Machines out there. In my previous post I already explained how it’s used and...

Understanding Blockchain Technology: An In-Depth Explanation and Industry Applications

Blockchain technology—it’s a term that’s been buzzing around for years, but what exactly is it? In a world that’s rapidly embracing digital transformation, understanding...

Most Popular