5

CVE-2012-1909

Exploit
The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which allows remote attackers to cause a denial of service (unspendable transaction) by leveraging the ability to create a duplicate coinbase transaction.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitcoin ≫ Bitcoin Core Update rc2 Version <= 0.4.4
Bitcoin ≫ Bitcoin Core Version 0.3.4
Bitcoin ≫ Bitcoin Core Version 0.3.5
Bitcoin ≫ Bitcoin Core Version 0.3.8
Bitcoin ≫ Bitcoin Core Version 0.3.10
Bitcoin ≫ Bitcoin Core Version 0.3.11
Bitcoin ≫ Bitcoin Core Version 0.3.12
Bitcoin ≫ Bitcoin Core Version 0.4.0
Bitcoin ≫ Bitcoin Core Version 0.4.1
Bitcoin ≫ Bitcoin Core Version 0.4.1 Update rc6
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.93% 0.853
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://en.bitcoin.it/wiki/CVEs
Vendor Advisory
http://r6.ca/blog/20120206T005236Z.html
http://sourceforge.net/mailarchive/forum.php?thread_name=CAPg%2BsBhmGHnMResVxPDZdfpmWTb9uqD0RrQD7oSXBQq7oHpm8g%40mail.gmail.com&forum_name=bitcoin-development
https://bitcointalk.org/index.php?topic=67738.0
https://bugs.gentoo.org/show_bug.cgi?id=407793
https://en.bitcoin.it/wiki/BIP_0030
Vendor Advisory
https://github.com/sipa/bitcoin/commit/a206b0ea12eb4606b93323268fc81a4f1f952531
Patch
Exploit