SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-18350

bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used.

MEDIUM 5.9EPSS 1.32%

Does this matter?

Lower severity and a low EPSS score (1.32%). Track it; it rarely justifies an emergency change on its own.

Description

bitcoind and Bitcoin-Qt prior to 0.15.1 have a stack-based buffer overflow if an attacker-controlled SOCKS proxy server is used. This results from an integer signedness error when the proxy server responds with an acknowledgement of an unexpected target domain name.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.32% probability · 69th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
bitcoin/bitcoin core
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.