← Back

CVE-2014-4502

nvd nist
Published: Jul 23, 2014Modified: May 6, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.

Affected (18)

1 product
Bfgminer
Sgminer
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 4.0.0
Configuration B
7 vulnerable
Vulnerable SoftwareAffected Versions
Sgminer Project
Up to 4.2.1
Version 4.0.0
Version 4.1.0
Version 4.1.153
Version 4.1.242
Version 4.1.271
Version 4.2.0
Configuration C
10 vulnerable
Vulnerable SoftwareAffected Versions
Bfgminer
Up to 3.2.9
Version 3.2.0
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8

Timeline

No history available yet.