PT-2020-13047 · Ledger · Ledger Live
Oded Leiba
+1
·
Published
2020-07-02
·
Updated
2020-07-08
·
CVE-2020-12119
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ledger Live versions prior to 2.7.0
Description
The issue arises from the software's failure to handle Bitcoin's Replace-By-Fee (RBF) properly. It incorrectly updates the user's balance by adding the value of unconfirmed transactions as soon as they are received, without waiting for confirmation. Furthermore, it does not adjust the balance when a transaction is canceled. This exposes users to various attacks, including basic double spending attacks, amplified double spending attacks, and Denial of Service (DoS) attacks, all without the user's consent.
Recommendations
For versions prior to 2.7.0, update to version 2.7.0 or later to resolve the issue.
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ledger Live