PT-2014-5935 · Sgminer+2 · Sgminer+2
Mick Ayzenberg
·
Published
2014-07-23
·
Updated
2015-08-28
·
CVE-2014-4502
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
sgminer versions prior to 4.2.2
cgminer versions prior to 4.3.5
BFGMiner versions prior to 4.1.0
Description
The issue is related to multiple heap-based buffer overflows in the
parse notify function. This can be triggered by remote pool servers sending a mining.subscribe response with a large or negative value in the Extranonc2 size parameter, followed by a crafted mining.notify request. The impact of this issue is unspecified.Recommendations
For sgminer versions prior to 4.2.2, update to version 4.2.2 or later.
For cgminer versions prior to 4.3.5, update to version 4.3.5 or later.
For BFGMiner versions prior to 4.1.0, update to version 4.1.0 or later.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bfgminer
Cgminer
Sgminer