libp2p-rendezvous 0.17.1 及更早版本未能验证发现响应中的注册 TTL 值,使得攻击者能够触发计时器算术溢出。恶意的 rendezvous 服务器可以发送一个具有无界(未限制)TTL 值的发现响应,导致客户端节点在计算过期计时器时发生进程崩溃(panic)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| libp2p | libp2p-rendezvous | ≤ 0.17.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| libp2p | libp2p-rendezvous | 0 ~ 0.17.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet