CVE-2012-4684: High severity bitcoin core vulnerability
The alert functionality in bitcoind and Bitcoin-Qt before 0.7.0 supports different character representations of the same signature data, but relies on a hash of this signature, which allows remote attackers to cause a denial of service (resource consumption) via a valid modified signature for a circulating alert.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-4684?
CVE-2012-4684 has a moderate severity rating as it can lead to denial of service through resource consumption.
How do I fix CVE-2012-4684?
To fix CVE-2012-4684, upgrade your Bitcoin software to version 0.7.0 or later.
Who is affected by CVE-2012-4684?
CVE-2012-4684 affects various versions of Bitcoin Core and Bitcoin-Qt prior to 0.7.0.
What type of attack does CVE-2012-4684 enable?
CVE-2012-4684 enables denial-of-service attacks through the use of valid modified signatures.
When was CVE-2012-4684 disclosed?
CVE-2012-4684 was disclosed in 2012, impacting older versions of Bitcoin software.