Description
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Remediation
References
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17145
https://github.com/bitcoin/bitcoin/blob/v0.16.2/doc/release-notes.md
https://invdos.net
https://invdos.net/paper/CVE-2018-17145.pdf
Related Vulnerabilities
CVE-2020-2299 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2018-15494 Vulnerability in maven package org.webjars.bower:dojox
CVE-2021-46364 Vulnerability in maven package info.magnolia:magnolia-core
CVE-2023-25330 Vulnerability in maven package com.baomidou:mybatis-plus-extension
CVE-2023-1454 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-common