Difference between revisions of "Common Vulnerabilities and Exposures"

From Bitcoin Wiki
Jump to: navigation, search
(Mention historical incidents, even if they didn't get CVEs)
Line 2: Line 2:
 
!style="width:14ex"| CVE
 
!style="width:14ex"| CVE
 
! Announced !! Affects !! Flaw !! Fixed in versions !! Links
 
! Announced !! Affects !! Flaw !! Fixed in versions !! Links
 +
|-
 +
|
 +
| 2010-07-28
 +
| wxBitcoin and bitcoind
 +
| OP_LSHIFT crash
 +
| 0.3.5
 +
| [[Incidents#LSHIFT and RETURN bugs|Incident]]
 +
|-
 +
|
 +
| 2010-07-29
 +
| wxBitcoin and bitcoind
 +
| Unlimited SigOp DoS
 +
| 0.3.?
 +
| [[Incidents#OP CHECKSIG abuse|Incident]]
 +
|-
 +
|
 +
| 2010-08-15
 +
| wxBitcoin and bitcoind
 +
| Combined output overflow
 +
| 0.3.11
 +
| [[Incidents#Value overflow|Incident]] [https://bitcointalk.org/index.php?topic=822.0 Discovery]
 +
|-
 +
|
 +
| 2010-09-29
 +
| wxBitcoin and bitcoind
 +
| Sending coins w/o sufficient fees
 +
| 0.3.13
 +
| [[Incidents#Micropayment contamination|Incident]] [http://www.bitcoin.org/smf/index.php?topic=1306.0 Initial reports]
 
|-
 
|-
 
| CVE-2011-4447
 
| CVE-2011-4447

Revision as of 18:15, 14 May 2012

CVE Announced Affects Flaw Fixed in versions Links
2010-07-28 wxBitcoin and bitcoind OP_LSHIFT crash 0.3.5 Incident
2010-07-29 wxBitcoin and bitcoind Unlimited SigOp DoS 0.3.? Incident
2010-08-15 wxBitcoin and bitcoind Combined output overflow 0.3.11 Incident Discovery
2010-09-29 wxBitcoin and bitcoind Sending coins w/o sufficient fees 0.3.13 Incident Initial reports
CVE-2011-4447 2011-11-11 wxBitcoin and bitcoind Wallet (non-)encryption 0.4.1, 0.5.0 Announcement Finding 0.5.0
CVE-2012-1909 2012-03-07 Bitcoin protocol Transaction overwriting BIP 30, 0.4.4, 0.5.3 Announcement Fix
CVE-2012-1910 2012-03-17 Bitcoin-Qt for Windows MingW non-multithreading 0.5.3.1, 0.5.4, 0.6.0rc4 Announcement
CVE-2012-2459 2012-05-14 bitcoind and Bitcoin-Qt TBD 0.4.6, 0.5.5, 0.6.0.7, and 0.6.2 Announcement