{"id":"GHSA-773q-5334-5gf9","aliases":["RUSTSEC-2021-0066"],"url":"https://o3.security/vulnerability/GHSA-773q-5334-5gf9","summary":"Memory over-allocation in evm-core","details":"Prior to the patch, when executing specific EVM opcodes related\nto memory operations that use `evm_core::Memory::copy_large`, the\ncrate can over-allocate memory when it is not needed, making it\npossible for an attacker to perform denial-of-service attack.\n\nThe flaw was corrected in commit `19ade85`.\n","published":"2021-08-25T20:55:36Z","modified":"2023-11-08T04:16:40.750878Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"evm-core","fixedVersion":"0.26.1"},{"ecosystem":"crates.io","name":"evm-core","fixedVersion":"0.25.1"},{"ecosystem":"crates.io","name":"evm-core","fixedVersion":"0.24.1"},{"ecosystem":"crates.io","name":"evm-core","fixedVersion":"0.23.1"},{"ecosystem":"crates.io","name":"evm-core","fixedVersion":"0.21.1"}],"fix":{"url":"https://github.com/rust-blockchain/evm/commit/19ade85","label":"rust-blockchain/evm@19ade85"},"references":[{"type":"WEB","url":"https://github.com/rust-blockchain/evm/commit/19ade85"},{"type":"PACKAGE","url":"https://github.com/rust-blockchain/evm"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2021-0066.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:16:40.750878Z"}}