PT-2019-10115 · Bitcoin+2 · Bitcoin Core+2
Published
2019-02-11
·
Updated
2019-10-03
·
CVE-2018-20587
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Bitcoin Core versions 0.12.0 through 0.17.1
Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229
Description:
The issue allows local users to exploit Incorrect Access Control, potentially leading to currency theft. This is achieved by binding the RPC IPv4 localhost port and forwarding requests to the IPv6 localhost port.
Recommendations:
For Bitcoin Core versions 0.12.0 through 0.17.1, update to a version outside of this range to resolve the issue.
For Bitcoin Knots versions 0.12.0 through 0.17.x before 0.17.1.knots20181229, update to version 0.17.1.knots20181229 or later to fix the problem.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Bitcoin Core
Bitcoin Knots