CVE-2018-19184: Null Pointer Dereference
cmd/evm/runner.go in Go Ethereum (aka geth) allows attackers to cause a denial of service (SEGV) via crafted bytecode. Specific Go Packages Affected github.com/ethereum/go-ethereum/cmd/evm
Other sources
cmd/evm/runner.go in Go Ethereum (aka geth) 1.8.17 allows attackers to cause a denial of service (SEGV) via crafted bytecode.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19184?
CVE-2018-19184 is a vulnerability in Go Ethereum (aka geth) 1.8.17 that allows attackers to cause a denial of service (SEGV) via crafted bytecode.
What is the severity of CVE-2018-19184?
CVE-2018-19184 has a severity level of high, with a CVSS score of 7.5.
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers through crafted bytecode, causing a denial of service (SEGV).
Which packages are affected by CVE-2018-19184?
The specific Go package affected is github.com/ethereum/go-ethereum/cmd/evm, with versions up to exclusive 1.8.14.
Is there a fix for CVE-2018-19184?
Yes, a fix for CVE-2018-19184 is available in Go Ethereum version 1.8.14.