GO-2022-0760
Ethermint vulnerable to DoS through unintended Contract Selfdestruct in github.com/crypto-org-chain/cronos
Quick fix
GO-2022-0760 — github.com/crypto-org-chain/cronos: upgrade to the fixed version with the command below.
go get github.com/crypto-org-chain/cronos@v0.7.1-rc2Details
Ethermint vulnerable to DoS through unintended Contract Selfdestruct in github.com/crypto-org-chain/cronos
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.7.1-rc2go get github.com/crypto-org-chain/cronos@v0.7.1-rc20Fixed in: 0.18.0go get github.com/evmos/ethermint@v0.18.00No fixed version published yet for github.com/evmos/evmos (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/evmos/evmos/v2 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/evmos/evmos/v3 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/evmos/evmos/v4 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/evmos/evmos/v5 (go modules). Pin to a known-safe version or switch to an alternative.
0No fixed version published yet for github.com/evmos/evmos/v6 (go modules). Pin to a known-safe version or switch to an alternative.
0Fixed in: 7.0.0go get github.com/evmos/evmos/v7@v7.0.00Fixed in: 0.18.0go get github.com/kava-labs/kava@v0.18.0References
- https://github.com/evmos/ethermint/security/advisories/GHSA-f92v-grc2-w2fg[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2022-35936[ADVISORY]
- https://github.com/evmos/ethermint/commit/144741832007a26dbe950512acbda4ed95b2a451[FIX]
- https://github.com/evmos/ethermint/blob/c9d42d667b753147977a725e98ed116c933c76cb/x/evm/keeper/statedb.go#L199-L203[WEB]