← Back

CVE-2016-10724

nvd nist
Published: Jul 5, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map. This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.

Affected (3)

3 products
Bitcoin Core
Bitcoin Qt
Bitcoind
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.13.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.13.0
Before 0.13.0

References (8)

Timeline

No history available yet.