7.5

CVE-2016-10725

In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts) because operations occur in the wrong order. This behavior occurs in the remote network alert system (deprecated since Q1 2016). This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BitcoinBitcoin Core Version < 0.13.0
BitcoinBitcoin-qt Version < 0.13.0
BitcoinBitcoind Version < 0.13.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.5% 0.826
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures
Vendor Advisory
https://bitcoin.org/en/posts/alert-key-and-vulnerabilities-disclosure
https://github.com/JinBean/CVE-Extension
https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-July/016189.html
Third Party Advisory