Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-12717 Cosmos Network Ethermint <= v0.4.0 is affected by cache lifecycle inconsistency in the EVM module. The bytecode set in a FAILED transaction wrongfully remains in memory(stateObject.code) and is further written to persistent store at the Endblock stage, which may be utilized to build honeypot contracts.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-03T20:11:28.461Z

Reserved: 2021-01-22T00:00:00

Link: CVE-2021-25836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-08T18:15:13.863

Modified: 2024-11-21T05:55:30.413

Link: CVE-2021-25836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.