CVE-2018-16733: Input Validation
Published Sep 8, 2018
·Updated
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/apitracer.go does not verify that the end block is after the start block.
Affected Software
2 affected componentsFixes available
go/github.com/ethereum/go-ethereum<1.8.14
1.8.14
Ethereum Go Ethereum<1.8.14
Event History
Sep 8, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 18, 2021
Advisory Published
06:38 PM
Frequently Asked Questions
1
What is CVE-2018-16733?
CVE-2018-16733 is a vulnerability in Go Ethereum (aka geth) before version 1.8.14 that allows an attacker to bypass security measures and execute arbitrary code.
2
How severe is CVE-2018-16733?
CVE-2018-16733 is considered a high severity vulnerability with a CVSS score of 7.5.
3
Which packages are affected by CVE-2018-16733?
The Go Ethereum package before version 1.8.14 and the Ethereum Go Ethereum package are affected by CVE-2018-16733.
4
How can I fix CVE-2018-16733?
To fix CVE-2018-16733, it is recommended to update to Go Ethereum version 1.8.14 or higher.
5
Where can I find more information about CVE-2018-16733?
More information about CVE-2018-16733 can be found on the NIST NVD website and in the GitHub repositories for Go Ethereum.