PT-2019-10115 · Bitcoin+2 · Bitcoin Core+2

Published

2019-02-11

·

Updated

2019-10-03

·

CVE-2018-20587

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Bitcoin Core versions 0.12.0 through 0.17.1 Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229
Description: The issue allows local users to exploit Incorrect Access Control, potentially leading to currency theft. This is achieved by binding the RPC IPv4 localhost port and forwarding requests to the IPv6 localhost port.
Recommendations: For Bitcoin Core versions 0.12.0 through 0.17.1, update to a version outside of this range to resolve the issue. For Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229, update to version 0.17.1.knots20181229 or later to fix the problem.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2019-1759
CVE-2018-20587

Affected Products

Alt Linux
Bitcoin Core
Bitcoin Knots