PT-2018-4890 · Bitcoin+1 · Bitcoin Knots+2
Achow101
+1
·
Published
2017-09-17
·
Updated
2020-03-18
·
CVE-2016-10724
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Bitcoin Core versions prior to 0.13.0
Bitcoin Knots versions prior to 0.13.0.knots20160814
Description
The issue allows for denial of service through memory exhaustion, triggered by the remote network alert system. This system is deprecated since Q1 2016. An attacker can exploit this by signing a message with a certain private key that had been known by unintended actors, due to an infinitely sized map. This affects not only Bitcoin Core but also other uses of the codebase, including Bitcoin Knots and many altcoins.
Recommendations
For Bitcoin Core versions prior to 0.13.0, update to version 0.13.0 or later.
For Bitcoin Knots versions prior to 0.13.0.knots20160814, update to version 0.13.0.knots20160814 or later.
Exploit
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Bitcoin Core
Bitcoin Knots