7.5

CVE-2012-1910

Exploit
Bitcoin-Qt 0.5.0.x before 0.5.0.5; 0.5.1.x, 0.5.2.x, and 0.5.3.x before 0.5.3.1; and 0.6.x before 0.6.0rc4 on Windows does not use MinGW multithread-safe exception handling, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted Bitcoin protocol messages.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BitcoinBitcoin-qt Version0.5.0 Updaterc1
   MicrosoftWindows
BitcoinBitcoin-qt Version0.5.0.4
   MicrosoftWindows
BitcoinBitcoin-qt Version0.5.1 Updaterc1
   MicrosoftWindows
BitcoinBitcoin-qt Version0.5.3.0
   MicrosoftWindows
BitcoinBitcoin Core Version0.5.0
   MicrosoftWindows
BitcoinBitcoin Core Version0.5.1
   MicrosoftWindows
BitcoinBitcoin Core Version0.5.2
   MicrosoftWindows
BitcoinBitcoin Core Version0.6.0
   MicrosoftWindows
BitcoinBitcoin Core Version0.6.0 Updaterc1
   MicrosoftWindows
BitcoinBitcoin Core Version0.6.0 Updaterc3
   MicrosoftWindows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.51% 0.903
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://en.bitcoin.it/wiki/CVEs
http://gavintech.blogspot.com/2012/03/full-disclosure-bitcoin-qt-on-windows.html
https://bitcointalk.org/index.php?topic=69120.0
https://github.com/bitcoin/bitcoin/commit/8864019f6d88b13d3442843d9e6ebeb8dd938831
Patch
Exploit