ColossusCoinXT through 1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade php5 | Oct 1, 2024 | Mar 17, 2019 |
| Oracle Solaris | — | Upgrade web/php-71 to version 7.1.25-0.175.3.36.0.19.0 on Solaris 11.3Upgrade web/php-56 to version 5.6.39-0.175.3.36.0.19.0 on Solaris 11.3Upgrade web/php-56 to version 5.6.39-11.4.5.0.1.2.0 on Solaris 11.4Upgrade web/php-71 to version 7.1.25-11.4.5.0.1.2.0 on Solaris 11.4 | Feb 20, 2019 | Feb 20, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub