Skip to content
Cosmopediaby Unity Nodes
DiscussionsSecurityVulnerability Coordination Retrospective: Cosmos Mainnet Security Advisory Lavender, 2020-04-09Forum ↗

Vulnerability Coordination Retrospective: Cosmos Mainnet Security Advisory Lavender, 2020-04-09

Security1 posts1,762 views7 likesLast activity Apr 2020
TE
tessrOP
Apr 2020 7

In March 2020, a high-severity security vulnerability impacting all versions of Tendermint Core was reported through the Tendermint Bug Bounty program. On April 9, 2020, at 14:00 UTC, Tendermint Core versions 0.33.3, 0.32.10 and 0.31.12 were released with patches for this vulnerability. Versions 0.37.9 and 0.38.3 of the Cosmos SDK and version 2.0.8 of Gaia were released shortly thereafter, with updates to use the latest release of Tendermint Core. The triage, remediation and communication processes were a collaborative effort by employees of All In Bits GmbH, Informal Inc., and Interchain GmbH. The Bugs The vulnerability that was reported demonstrated a pair of flaws in Tendermint logic that, when exploited, could cause a remote panic. These bugs could be exploited by an attacker sending spurious bytes to a target node after the handshake process, causing a memory leak in the target node and ultimately a panic and crash. This vulnerability would have allowed an attacker to carry out a Denial of Service attack against public nodes on Tendermint-powered networks, exploriting one of two vectors. Denial of Service 1 Tendermint 0.33.2 and earlier did not limit the number of…

Excerpt (1197 of 5836 characters). Read the whole post on the forum ↗

← Back to Discussions