Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1odzR2LTV4NGgtYzN4bc0Vhg
Transaction validity oversight in pallet-ethereum
Impact
A bug in pallet-ethereum
can cause invalid transactions to be included in the Ethereum block state in pallet-ethereum
due to not validating the input data size. Any invalid transactions included this way have no possibility to alter the internal Ethereum or Substrate state. The transaction will appear to have be included, but is of no effect as it is rejected by the EVM engine. The impact is further limited by Substrate extrinsic size constraints.
Patches
Patches are applied in PR #465.
Workarounds
None.
References
Patch PR: https://github.com/paritytech/frontier/pull/465
For more information
If you have any questions or comments about this advisory:
- Open an issue in the Frontier repo
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1odzR2LTV4NGgtYzN4bc0Vhg
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: over 2 years ago
Updated: 10 months ago
CVSS Score: 5.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Identifiers: GHSA-hw4v-5x4h-c3xm, CVE-2021-39193
References:
- https://github.com/paritytech/frontier/security/advisories/GHSA-hw4v-5x4h-c3xm
- https://github.com/paritytech/frontier/commit/dd112e
- https://nvd.nist.gov/vuln/detail/CVE-2021-39193
- https://github.com/paritytech/frontier/pull/465
- https://github.com/paritytech/frontier/pull/465/commits/8a2b890a2fb477d5fedd0e4335b00623832849ae
- https://github.com/paritytech/frontier/commit/0b962f218f0cdd796dadfe26c3f09e68f7861b26
- https://github.com/advisories/GHSA-hw4v-5x4h-c3xm
Blast Radius: 1.0
Affected Packages
cargo:frontier
Dependent packages: 0Dependent repositories: 0
Downloads: 1,435 total
Affected Version Ranges: <= 0.1.0
No known fixed version
All affected versions: 0.0.0, 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.1.0