EF Blog

ETH top background starting image
ETH bottom background ending image
Skip to content

Security Advisory [eth (cpp-ethereum) potentially vulnerable if running with UPnP enabled]

Posted by Gustav Simonsson on October 10, 2015

Security Advisory [eth (cpp-ethereum) potentially vulnerable if running with UPnP enabled]
Affected configurations: Issue reported for eth (cpp-ethereum).
Likelihood: Medium
Severity: High
Impact: Potentially achieve remote code execution on a machine running eth (cpp-ethereum)
Details:
A vulnerability found in the MiniUPnP library can potentially affect eth clients running with UPnP enabled.
Effects on expected chain reorganisation depth: none
Remedial action taken by Ethereum: We are verifying whether this can indeed affect cpp-ethereum and will post an update shortly.
Proposed temporary workaround: Only run eth (cpp-ethereum) with UPNP disabledby passing --upnp off to eth.
ADVISORY: Disable UPnP if running the eth client (cpp-ethereum).

Subscribe to Protocol Announcements

Sign up to receive email notifications for protocol-related announcements, such as network upgrades, FAQs or security issues. You can opt-out of these at any time.


Categories