ontio / ontology

Official Go implementation of the Ontology protocol. https://dev-docs.ont.io/#/
GNU Lesser General Public License v3.0
829 stars 290 forks source link

CVE-2022-44797 with btcd #1431

Open dwickwire opened 1 year ago

dwickwire commented 1 year ago

Hello,

btcd before < 0.23.2 has CRITICAL CVE-2022-44797, btcd mishandles witness size checking. Patched in v0.23.3

Just need to bump here:

https://github.com/ontio/ontology/blob/16b2a65d0e271510f6b8980972ee84c6bfa045ce/go.mod#L36