Skip to content

Commit dbbdb3a

Browse files
committed
data/reports: add vulnerable_at to GO-2021-0105.yaml
Also fixes package name Aliases: CVE-2020-26265, GHSA-xw37-57qp-9mm4 Updates #105 Change-Id: I0e15f83d189ba546b7961cd9f2ab055908a9b9cf Reviewed-on: https://go-review.googlesource.com/c/vulndb/+/465799 Run-TryBot: Tatiana Bradley <[email protected]> TryBot-Result: Gopher Robot <[email protected]> Reviewed-by: Tim King <[email protected]>
1 parent 72bcb35 commit dbbdb3a

File tree

2 files changed

+22
-3
lines changed

2 files changed

+22
-3
lines changed

data/osv/GO-2021-0105.json

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,8 +32,17 @@
3232
"ecosystem_specific": {
3333
"imports": [
3434
{
35-
"path": "github.com/ethereum/go-ethereum/core",
35+
"path": "github.com/ethereum/go-ethereum/core/state",
3636
"symbols": [
37+
"StateDB.AddBalance",
38+
"StateDB.CreateAccount",
39+
"StateDB.GetOrNewStateObject",
40+
"StateDB.SetBalance",
41+
"StateDB.SetCode",
42+
"StateDB.SetNonce",
43+
"StateDB.SetState",
44+
"StateDB.SetStorage",
45+
"StateDB.SubBalance",
3746
"StateDB.createObject"
3847
]
3948
}

data/reports/GO-2021-0105.yaml

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,11 +3,21 @@ modules:
33
versions:
44
- introduced: 1.9.4
55
- fixed: 1.9.20
6+
vulnerable_at: 1.9.20-0.20200821114314-b68929caee77
67
packages:
7-
- package: github.com/ethereum/go-ethereum/core
8+
- package: github.com/ethereum/go-ethereum/core/state
89
symbols:
910
- StateDB.createObject
10-
skip_fix: 'TODO: fill this out [or set vulnerable_at to derive symbols]'
11+
derived_symbols:
12+
- StateDB.AddBalance
13+
- StateDB.CreateAccount
14+
- StateDB.GetOrNewStateObject
15+
- StateDB.SetBalance
16+
- StateDB.SetCode
17+
- StateDB.SetNonce
18+
- StateDB.SetState
19+
- StateDB.SetStorage
20+
- StateDB.SubBalance
1121
description: |
1222
Due to an incorrect state calculation, a specific set of
1323
transactions could cause a consensus disagreement,

0 commit comments

Comments
 (0)