Note:
This project will be discontinued after December 13, 2021. [more]
2020-09-10
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Products | Bcoin, Bitcoin_core, Bitcoin_knots, Btcd, Dcrd, Litecoin, Namecoin_core |
Type | Uncontrolled Resource Consumption (CWE-400) |
First patch | - None (likely due to unavailable code) |
Links |
• https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17145
• https://invdos.net/paper/CVE-2018-17145.pdf • https://invdos.net • https://github.com/bitcoin/bitcoin/blob/v0.16.2/doc/release-notes.md |