#VU3912 Improper input validation in Bitcoin-Qt


Published: 2017-01-10 | Updated: 2017-03-14

Vulnerability identifier: #VU3912

Vulnerability risk: Low

CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2012-4682

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Vulnerable software:
Bitcoin-Qt
Other software / Other software solutions

Vendor: Bitcoin

Description
The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to unknown error that allows a remote attacker to trigger the application to crash.

Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Mitigation
The vulnerability is fixed in the following versions: 0.4.7rc3, 0.5.6rc3, 0.6.0.9rc1, and 0.6.3rc1.

Vulnerable software versions

Bitcoin-Qt: 0.4.7 rc2 - 0.6.2.2


External links
http://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2012-4682
http://bugs.gentoo.org/show_bug.cgi?id=435216


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability