Junglewise Threat Intelligence

ApeWorX eth-abi recursive pointer DoS

Severity: medium · Published 2024-03-05

Vendors: PyPI.

Executive brief

eth-abi is a Python library used by Ethereum applications to encode and decode data according to the Ethereum contract ABI standard. A flaw in handling deeply nested array types allows an attacker to craft a malicious payload that causes excessive recursion, leading to a denial of service (crash or hang) in any application decoding untrusted data. This could affect Ethereum tools, DeFi protocols, and blockchain infrastructure that use this library.

Technical details

This vulnerability is a recursive pointer handling flaw (CWE-1285) in eth-abi's decode function. The root cause is improper validation of indices and offsets when parsing deeply nested array type specifications. An attacker can supply a specially crafted hex-encoded payload with recursively nested uint256 array types (e.g., `uint256[][][][][][][][][][]`) that triggers unbounded recursion during type decoding. The attack requires no authentication—any caller can invoke the decode function with a malicious payload. Exploitation results in a stack overflow or excessive memory consumption, crashing the application. The vulnerability was patched in version 5.0.1; users of eth-abi <= 5.0.0 are affected.

Affected products

  • ApeWorX eth-abi <= 5.0.0

Timeline

  • 2024-03-05: disclosed: Published to GitHub Advisory Database
  • 2024-03-04: patched: Patch released in version 5.0.1

References