Validator parsing discrepancy due to string encoding in NPM slp-validate 1.0.0
Vulnerability Description
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-16761
Credits & Attribution
No credits recorded in the NVD database.
References
More from simpleledger
View All →Affected Vendor
simpleledger
View all reports →