Vulnerability Coordination Retrospective: Cosmos Mainnet Security Advisory Lavender, 2020-04-09
In March 2020, a high-severity security vulnerability impacting all versions of Tendermint Core was reported through the Tendermint Bug Bounty program. On April 9, 2020, at 14:00 UTC, Tendermint Core versions 0.33.3, 0.32.10 and 0.31.12 were released with patches for this vulnerability. Versions 0.37.9 and 0.38.3 of the Cosmos SDK and version 2.0.8 of Gaia were released shortly thereafter, with updates to use the latest release of Tendermint Core. The triage, remediation and communication processes were a collaborative effort by employees of All In Bits GmbH, Informal Inc., and Interchain GmbH. The Bugs The vulnerability that was reported demonstrated a pair of flaws in Tendermint logic that, when exploited, could cause a remote panic. These bugs could be exploited by an attacker sending spurious bytes to a target node after the handshake process, causing a memory leak in the target node and ultimately a panic and crash. This vulnerability would have allowed an attacker to carry out a Denial of Service attack against public nodes on Tendermint-powered networks, exploriting one of two vectors. Denial of Service 1 Tendermint 0.33.2 and earlier did not limit the number of…
Excerpt (1197 of 5836 characters). Read the whole post on the forum ↗