Miggo Logo

GHSA-mcq2-w56r-5w2w: Daemon panics when processing certain blocks

N/A

CVSS Score

Basic Information

CVE ID
-
EPSS Score
-
CWE
-
Published
4/8/2022
Updated
1/11/2023
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
-
Package NameEcosystemVulnerable VersionsFirst Patched Version
github.com/ipld/go-ipfsgo>= 0.12.0, < 0.12.20.12.2
github.com/ipld/go-ipfsgo< 0.11.10.11.1

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The provided vulnerability information indicates the root cause lies in the 'go-codec-dagpb' dependency rather than directly within go-ipfs functions. While go-ipfs functions would call into the vulnerable dependency during IPLD graph traversal and block processing, the advisory and descriptions provided do not include specific patch details or code changes to go-ipfs that would allow identification of exact vulnerable functions within the go-ipfs codebase itself. The patches mentioned focus on dependency version updates rather than code modifications in go-ipfs. Without explicit evidence of vulnerable functions in go-ipfs from provided patches or code snippets, we cannot confidently identify specific functions meeting the criteria.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

### Imp**t *o-ip*s no**s wit* v*rsions *.**.*, *.**.*, *.**.*, or *.**.* **n *r*s* w**n tryin* to tr*v*rs* **rt*in m*l*orm** *r*p*s *u* to *n issu* in t** *o-*o***-***p* **p*n**n*y. Vuln*r**l* no**s t**t work wit* t**s* m*l*orm** *r*p*s m*y *r*s* l*

Reasoning

T** provi*** vuln*r**ility in*orm*tion in*i**t*s t** root **us* li*s in t** '*o-*o***-***p*' **p*n**n*y r*t**r t**n *ir**tly wit*in `*o-ip*s` *un*tions. W*il* `*o-ip*s` *un*tions woul* **ll into t** vuln*r**l* **p*n**n*y *urin* IPL* *r*p* tr*v*rs*l *