CVE-2016-10724 Detail Modified This vulnerability has been modified since it was last analyzed by the NVD. It is awaiting reanalysis which may result in further changes to the information provided. Current Description Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map. This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.

View Analysis Description Analysis Description Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map. This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins. Severity CVSS Version 3.x CVSS Version 2.0



CVSS 3.x Severity and Metrics:

NIST: NVD Base Score: 7.5 HIGH Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS 2.0 Severity and Metrics:



NIST: NVD Base Score: 7.8 HIGH Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:C) Weakness Enumeration CWE-ID CWE Name Source CWE-400 Uncontrolled Resource Consumption NIST Known Affected Software Configurations Switch to CPE 2.2 CPEs loading, please wait. Denotes Vulnerable Software

Are we missing a CPE here? Please let us know.

Change History 3 change records found show changes CPE Deprecation Remap 3/18/2020 1:7:15 PM Action Type Old Value New Value Changed CPE Configuration OR *cpe:2.3:a:bitcoincore:bitcoin_core:*:*:*:*:*:*:*:* versions from (excluding) 0.13.0



OR *cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:* versions from (excluding) 0.13.0



CVE Modified by MITRE 7/17/2019 3:15:11 PM Action Type Old Value New Value Added Reference https://bitcoin.org/en/posts/alert-key-and-vulnerabilities-disclosure [No Types Assigned]



Added Reference https://github.com/JinBean/CVE-Extension [No Types Assigned]



Initial Analysis 8/27/2018 8:16:52 AM Action Type Old Value New Value Added CPE Configuration OR *cpe:2.3:a:bitcoin:bitcoin-qt:*:*:*:*:*:*:*:* versions up to (excluding) 0.13.0 *cpe:2.3:a:bitcoin:bitcoind:*:*:*:*:*:*:*:* versions up to (excluding) 0.13.0



Added CPE Configuration OR *cpe:2.3:a:bitcoincore:bitcoin_core:*:*:*:*:*:*:*:* versions up to (excluding) 0.13.0



Added CVSS V2 (AV:N/AC:L/Au:N/C:N/I:N/A:C)



Added CVSS V3 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H



Added CWE CWE-400



Changed Reference Type https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures No Types Assigned



https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures Vendor Advisory



Changed Reference Type https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-July/016189.html No Types Assigned



https://lists.linuxfoundation.org/pipermail/bitcoin-dev/2018-July/016189.html Third Party Advisory



Quick Info CVE Dictionary Entry:

CVE-2016-10724

NVD Published Date:

07/05/2018

NVD Last Modified:

03/18/2020

Source:

MITRE

