aboutsummaryrefslogtreecommitdiff
path: root/.travis.yml
diff options
context:
space:
mode:
authoranonimal <anonimal@getmonero.org>2019-03-09 09:11:44 +0000
committermoneromooo-monero <moneromooo-monero@users.noreply.github.com>2019-06-14 08:48:01 +0000
commit3c953d53696d9ccdd195e6a2f02578a154266882 (patch)
treeee0004259555955445b28e5c18fe7fe1869a06ca /.travis.yml
parentepee: basic sanity check on allocation size from untrusted source (diff)
downloadmonero-3c953d53696d9ccdd195e6a2f02578a154266882.tar.xz
cryptonote_protocol_handler: prevent potential DoS
Essentially, one can send such a large amount of IDs that core exhausts all free memory. This issue can theoretically be exploited using very large CN blockchains, such as Monero. This is a partial fix. Thanks and credit given to CryptoNote author 'cryptozoidberg' for collaboration and the fix. Also thanks to 'moneromooo'. Referencing HackerOne report #506595.
Diffstat (limited to '.travis.yml')
0 files changed, 0 insertions, 0 deletions