PT-2014-5935 · Sgminer+2 · Sgminer+2

Mick Ayzenberg

·

Published

2014-07-23

·

Updated

2015-08-28

·

CVE-2014-4502

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions sgminer versions prior to 4.2.2 cgminer versions prior to 4.3.5 BFGMiner versions prior to 4.1.0
Description The issue is related to multiple heap-based buffer overflows in the parse notify function. This can be triggered by remote pool servers sending a mining.subscribe response with a large or negative value in the Extranonc2 size parameter, followed by a crafted mining.notify request. The impact of this issue is unspecified.
Recommendations For sgminer versions prior to 4.2.2, update to version 4.2.2 or later. For cgminer versions prior to 4.3.5, update to version 4.3.5 or later. For BFGMiner versions prior to 4.1.0, update to version 4.1.0 or later.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4502

Affected Products

Bfgminer
Cgminer
Sgminer