CVE-2014-4502

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bfgminer:bfgminer:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:sgminer_project:sgminer:*:*:*:*:*:*:*:*
cpe:2.3:a:sgminer_project:sgminer:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:sgminer_project:sgminer:4.1.0:*:*:*:*:*:*:*
cpe:2.3:a:sgminer_project:sgminer:4.1.153:*:*:*:*:*:*:*
cpe:2.3:a:sgminer_project:sgminer:4.1.242:*:*:*:*:*:*:*
cpe:2.3:a:sgminer_project:sgminer:4.1.271:*:*:*:*:*:*:*
cpe:2.3:a:sgminer_project:sgminer:4.2.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:bfgminer:bfgminer:*:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.4:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.5:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.6:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.7:*:*:*:*:*:*:*
cpe:2.3:a:bfgminer:bfgminer:3.2.8:*:*:*:*:*:*:*

History

21 Nov 2024, 02:10

Type Values Removed Values Added
References () http://seclists.org/fulldisclosure/2014/Jul/119 - () http://seclists.org/fulldisclosure/2014/Jul/119 -
References () http://www.securityfocus.com/bid/68831 - () http://www.securityfocus.com/bid/68831 -
References () https://github.com/ckolivas/cgminer/commit/e1c5050734123973b99d181c45e74b2cbb00272e - Exploit, Patch () https://github.com/ckolivas/cgminer/commit/e1c5050734123973b99d181c45e74b2cbb00272e - Exploit, Patch
References () https://github.com/luke-jr/bfgminer/commit/ff7f30129f15f7a2213f8ced0cd65c9a331493d9 - Exploit, Patch () https://github.com/luke-jr/bfgminer/commit/ff7f30129f15f7a2213f8ced0cd65c9a331493d9 - Exploit, Patch
References () https://github.com/sgminer-dev/sgminer/commit/bac5831b355f916e0696b7bbcccfc51c057b729a - Exploit, Patch () https://github.com/sgminer-dev/sgminer/commit/bac5831b355f916e0696b7bbcccfc51c057b729a - Exploit, Patch
References () https://github.com/sgminer-dev/sgminer/issues/258 - () https://github.com/sgminer-dev/sgminer/issues/258 -

Information

Published : 2014-07-23 14:55

Updated : 2024-11-21 02:10


NVD link : CVE-2014-4502

Mitre link : CVE-2014-4502

CVE.ORG link : CVE-2014-4502


JSON object : View

Products Affected

bfgminer

  • bfgminer

sgminer_project

  • sgminer
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer