CVE-2017-14451: Critical severity ethereum blockchain vulnerability
An exploitable out-of-bounds read vulnerability exists in libevm (Ethereum Virtual Machine) of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read which can subsequently trigger an out-of-bounds write resulting in remote code execution. An attacker can create/send malicious smart contract to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-14451?
CVE-2017-14451 is an exploitable out-of-bounds read vulnerability in libevm (Ethereum Virtual Machine) of CPP-Ethereum.
How does CVE-2017-14451 work?
CVE-2017-14451 can be exploited by using a specially crafted smart contract code that causes an out-of-bounds read, which can lead to an out-of-bounds write and remote code execution.
What software is affected by CVE-2017-14451?
The Ethereum Ethereum software is affected by CVE-2017-14451.
What is the severity of CVE-2017-14451?
CVE-2017-14451 has a severity rating of critical (10).
How can CVE-2017-14451 be fixed?
There is no known fix for CVE-2017-14451 at this time. It is recommended to update to the latest version of the software when a fix becomes available.