Common Vulnerabilities and Exposures: Difference between revisions

From Bitcoin Wiki
Jump to navigation Jump to search
Luke-jr (talk | contribs)
No edit summary
Luke-jr (talk | contribs)
Mention historical incidents, even if they didn't get CVEs
Line 2: Line 2:
!style="width:14ex"| CVE
!style="width:14ex"| CVE
! Announced !! Affects !! Flaw !! Fixed in versions !! Links
! Announced !! Affects !! Flaw !! Fixed in versions !! Links
|-
|
| 2010-07-28
| wxBitcoin and bitcoind
| OP_LSHIFT crash
| 0.3.5
| [[Incidents#LSHIFT and RETURN bugs|Incident]]
|-
|
| 2010-07-29
| wxBitcoin and bitcoind
| Unlimited SigOp DoS
| 0.3.?
| [[Incidents#OP CHECKSIG abuse|Incident]]
|-
|
| 2010-08-15
| wxBitcoin and bitcoind
| Combined output overflow
| 0.3.11
| [[Incidents#Value overflow|Incident]] [https://bitcointalk.org/index.php?topic=822.0 Discovery]
|-
|
| 2010-09-29
| wxBitcoin and bitcoind
| Sending coins w/o sufficient fees
| 0.3.13
| [[Incidents#Micropayment contamination|Incident]] [http://www.bitcoin.org/smf/index.php?topic=1306.0 Initial reports]
|-
|-
| CVE-2011-4447
| CVE-2011-4447

Revision as of 18:15, 14 May 2012

CVE Announced Affects Flaw Fixed in versions Links
2010-07-28 wxBitcoin and bitcoind OP_LSHIFT crash 0.3.5 Incident
2010-07-29 wxBitcoin and bitcoind Unlimited SigOp DoS 0.3.? Incident
2010-08-15 wxBitcoin and bitcoind Combined output overflow 0.3.11 Incident Discovery
2010-09-29 wxBitcoin and bitcoind Sending coins w/o sufficient fees 0.3.13 Incident Initial reports
CVE-2011-4447 2011-11-11 wxBitcoin and bitcoind Wallet (non-)encryption 0.4.1, 0.5.0 Announcement Finding 0.5.0
CVE-2012-1909 2012-03-07 Bitcoin protocol Transaction overwriting BIP 30, 0.4.4, 0.5.3 Announcement Fix
CVE-2012-1910 2012-03-17 Bitcoin-Qt for Windows MingW non-multithreading 0.5.3.1, 0.5.4, 0.6.0rc4 Announcement
CVE-2012-2459 2012-05-14 bitcoind and Bitcoin-Qt TBD 0.4.6, 0.5.5, 0.6.0.7, and 0.6.2 Announcement