ZeroHour

CVE-2017-18350

CVSS 3.1
5.9 medium
EPSS
1%p69
Published
()
Modified
Description

bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.

Vendors
bitcoin
Products
bitcoin core
Weakness
CWE-120
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.