CVE-2020-26264 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Denial of service |
Description | In go-ethereum before version 1.9.25, a denial-of-service vulnerability can make a LES server crash via malicious GetProofsV2 request from a connected LES client. This vulnerability only concerns users explicitly enabling the LES server; disabling LES prevents the exploit. The vulnerability was patched in version 1.9.25. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-1351 | go-ethereum | 1.9.24-2 | 1.9.25-1 | Medium | Fixed |
Notes |
---|
Workaround ========== This issue can be mitigated by disabling the LES server. |