QID 983785
QID 983785: Nodejs (npm) Security Update for ethereumjs-vm (GHSA-2mw7-wggm-m6w3)
ethereumjs-vm 2.4.0 allows attackers to cause a denial of service (vm.runCode failure and REVERT) via a "code: Buffer.from(my_code, 'hex')" attribute.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2mw7-wggm-m6w3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2mw7-wggm-m6w3 -
github.com/advisories/GHSA-2mw7-wggm-m6w3
CVEs related to QID 983785
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2mw7-wggm-m6w3 | ethereumjs-vm |
|