Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2jg-6vfx-xj22

Опубликовано: 18 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.

EPSS

Процентиль: 83%
0.01938
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffer overflow and significant data leak, a different vulnerability than CVE-2019-12107. In Bitcoin Core before 0.12, remote code execution was possible in conjunction with CVE-2015-6031 exploitation.

CVSS3: 9.8
debian
около 1 года назад

miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other ...

EPSS

Процентиль: 83%
0.01938
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-120