漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
ZEBRA: Permanent Block Discovery Halt via Gossip Queue Saturation and Syncer Poisoning
Vulnerability Description
ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Zebra's block discovery pipeline allows an unauthenticated remote attacker to permanently halt all new block discovery on a targeted node. The attack exploits three independent weaknesses in the gossip, syncer, and download subsystems — all exercisable from a single TCP connection — to create a monotonically growing block deficit that never self-heals. This issue has been patched in version 4.4.0.
CVSS Information
N/A
Vulnerability Type
不加限制或调节的资源分配
Vulnerability Title
zebra 安全漏洞
Vulnerability Description
zebra是Zcash Foundation开源的一个用Rust编写的Zcash全节点实现。 Zebra 4.4.0之前版本存在安全漏洞,该漏洞源于区块发现管道中的复合拒绝服务漏洞,可能导致远程攻击者永久停止新区块发现。
CVSS Information
N/A
Vulnerability Type
N/A