NA

CVE-2015-6964

Published: 25/09/2023 Updated: 26/09/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

MultiBit HD prior to 0.1.2 allows malicious users to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occurs because there is no message authentication code (MAC).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

multibit multibit hd

Github Repositories

BritExploit (CVE-2015-6964) This is the brute force script to find unspendable bitcoin addresses of a format that allows them to be inserted into the Fee Address List BRITv1/Multibit 011 and earlier use to send fees to the Multibit developers For a full explanation of the attack see multibitorg/blog/2015/07/25/bit-flipping-attackhtml