bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.
References
Configurations
History
07 Nov 2023, 02:41
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Information
Published : 2020-03-12 21:15
Updated : 2024-02-28 17:47
NVD link : CVE-2017-18350
Mitre link : CVE-2017-18350
CVE.ORG link : CVE-2017-18350
JSON object : View
Products Affected
bitcoin
- bitcoin_core
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')