The parse_notify function in util.c in sgminer prior to 4.2.2 and cgminer 3.3.0 up to and including 4.0.1 allows man-in-the-middle malicious users to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
sgminer project sgminer 4.2.0 |
||
sgminer project sgminer 4.1.242 |
||
sgminer project sgminer 4.1.153 |
||
sgminer project sgminer 4.1.0 |
||
sgminer project sgminer 4.0.0 |
||
sgminer project sgminer |
||
sgminer project sgminer 4.1.271 |
||
cgminer project cgminer 3.3.0 |
||
cgminer project cgminer 3.3.2 |
||
cgminer project cgminer 3.3.4 |
||
cgminer project cgminer 3.5.0 |
||
cgminer project cgminer 3.6.0 |
||
cgminer project cgminer 3.7.2 |
||
cgminer project cgminer 3.8.1 |
||
cgminer project cgminer 3.9.0 |
||
cgminer project cgminer 3.11.0 |
||
cgminer project cgminer 3.12.1 |
||
cgminer project cgminer 3.6.2 |
||
cgminer project cgminer 3.6.3 |
||
cgminer project cgminer 3.6.4 |
||
cgminer project cgminer 3.7.0 |
||
cgminer project cgminer 3.12.2 |
||
cgminer project cgminer 3.12.3 |
||
cgminer project cgminer 4.0.0 |
||
cgminer project cgminer 4.0.1 |
||
cgminer project cgminer 3.4.0 |
||
cgminer project cgminer 3.4.1 |
||
cgminer project cgminer 3.4.2 |
||
cgminer project cgminer 3.4.3 |
||
cgminer project cgminer 3.8.2 |
||
cgminer project cgminer 3.8.3 |
||
cgminer project cgminer 3.8.4 |
||
cgminer project cgminer 3.8.5 |
||
cgminer project cgminer 3.3.1 |
||
cgminer project cgminer 3.3.3 |
||
cgminer project cgminer 3.5.1 |
||
cgminer project cgminer 3.6.1 |
||
cgminer project cgminer 3.7.1 |
||
cgminer project cgminer 3.8.0 |
||
cgminer project cgminer 3.10.0 |
||
cgminer project cgminer 3.12.0 |