PT-2013-1693 · Bitcoin · Bitcoin-Qt+1

Enochian

+1

·

Published

2013-03-12

·

Updated

2020-03-18

·

CVE-2012-4684

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions bitcoind and Bitcoin-Qt versions prior to 0.7.0
Description The issue concerns the alert functionality in the affected software, which improperly handles different character representations of the same signature data. It relies on a hash of this signature, allowing remote attackers to cause a denial of service through resource consumption by providing a valid modified signature for a circulating alert.
Recommendations For versions prior to 0.7.0, update to version 0.7.0 or later to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-4684

Affected Products

Bitcoin-Qt
Bitcoind