mirror of https://github.com/bitcoin/bitcoin
This fixes two alert system vulnerabilities found by Sergio Lerner; you could send peers unlimited numbers of invalid alert message to try to either fill up their debug.log with messages and/or keep their CPU busy checking signatures. Fixed by disconnecting/banning peers if they send 10 or more bad (invalid/expired/cancelled) alerts.pull/1729/head
parent
772351b0d5
commit
d5a52d9b3e
Loading…
Reference in new issue