← Back

CVE-2016-10725

nvd nist
Published: Jul 5, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because operations occur in the wrong order. This behavior occurs in the remote network alert system (deprecated since Q1 2016). This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.

Affected (3)

3 products
Bitcoin Core
Bitcoin Qt
Bitcoind
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.13.0
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.13.0
Before 0.13.0

Related CWEs

References (8)

Timeline

No history available yet.