CVE-2018-20587: Medium severity bitcoin vulnerability
Bitcoin Core 0.12.0 through 0.17.1 and Bitcoin Knots 0.12.0 through 0.17.x before 0.17.1.knots20181229 have Incorrect Access Control. Local users can exploit this to steal currency by binding the RPC IPv4 localhost port, and forwarding requests to the IPv6 localhost port.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20587?
CVE-2018-20587 has a moderate severity level due to potential unauthorized access to currency by local users.
How do I fix CVE-2018-20587?
To fix CVE-2018-20587, upgrade Bitcoin Core to version 0.17.1 or later and Bitcoin Knots to version 0.17.1.knots20181229 or later.
Who is affected by CVE-2018-20587?
CVE-2018-20587 affects users of Bitcoin Core versions 0.12.0 to 0.17.1 and Bitcoin Knots versions 0.12.0 to 0.17.x before 0.17.1.knots20181229.
What is the exploit mechanism for CVE-2018-20587?
The exploit mechanism for CVE-2018-20587 involves local users binding the RPC IPv4 localhost port and forwarding requests to the IPv6 localhost port.
Is CVE-2018-20587 a remote or local vulnerability?
CVE-2018-20587 is a local vulnerability that requires local user access to exploit.