CVE-2017-14457

HIGH

CPP-Ethereum - Info Disclosure/DoS

Title source: llm
STIX 2.1

Description

An exploitable information leak/denial of service vulnerability exists in the libevm (Ethereum Virtual Machine) `create2` opcode handler of CPP-Ethereum. A specially crafted smart contract code can cause an out-of-bounds read leading to memory disclosure or denial of service. An attacker can create/send malicious a smart contract to trigger this vulnerability.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102475

Scores

CVSS v3 8.2
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
ethereum/ethereum_virtual_machine
Published Jan 19, 2018
Tracked Since Feb 18, 2026