PT-2019-10115 · Bitcoin+2 · Bitcoin Core+2

Publicado

2019-02-11

·

Atualizado

2019-10-03

·

CVE-2018-20587

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Bitcoin Core versions 0.12.0 through 0.17.1 Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229
Description: The issue allows local users to exploit Incorrect Access Control, potentially leading to currency theft. This is achieved by binding the RPC IPv4 localhost port and forwarding requests to the IPv6 localhost port.
Recommendations: For Bitcoin Core versions 0.12.0 through 0.17.1, update to a version outside of this range to resolve the issue. For Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229, update to version 0.17.1.knots20181229 or later to fix the problem.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

ALT-PU-2019-1759
CVE-2018-20587

Produtos afetados

Alt Linux
Bitcoin Core
Bitcoin Knots