PT-2019-10115 · Bitcoin+2 · Bitcoin Core+2
Publicado
2019-02-11
·
Atualizado
2019-10-03
·
CVE-2018-20587
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Bitcoin Core versions 0.12.0 through 0.17.1
Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229
Description:
The issue allows local users to exploit Incorrect Access Control, potentially leading to currency theft. This is achieved by binding the RPC IPv4 localhost port and forwarding requests to the IPv6 localhost port.
Recommendations:
For Bitcoin Core versions 0.12.0 through 0.17.1, update to a version outside of this range to resolve the issue.
For Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229, update to version 0.17.1.knots20181229 or later to fix the problem.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Bitcoin Core
Bitcoin Knots