漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Klever-Go MultiDataInterceptor: remote OOM via crafted compressed P2P payload
Vulnerability Description
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any peer that participates in a topic served by MultiDataInterceptor to allocate multi-gigabyte heaps on the receiving node from a sub-50 KiB gossip payload. A single packet is sufficient to OOM-kill a validator with conventional memory provisioning. Fleet-wide application affects chain liveness. This vulnerability is fixed in 1.7.17.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
Vulnerability Type
对高度压缩数据的处理不恰当(数据放大攻击)
Vulnerability Title
Klever Blockchain 安全漏洞
Vulnerability Description
Klever Blockchain是Klever开源的一款高性能区块链网络实现。 Klever Blockchain 1.7.17之前版本存在安全漏洞,该漏洞源于Batch.Decompress函数中远程未认证拒绝服务问题,可能导致任何参与MultiDataInterceptor服务主题的节点从小于50 KiB的gossip有效载荷中分配多GB堆内存,单个数据包足以导致常规内存配置的验证器OOM崩溃,影响链活性。
CVSS Information
N/A
Vulnerability Type
N/A