6.5
CVSSv2

CVE-2018-10058

Published: 05/06/2018 Updated: 24/08/2020
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote malicious user to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cgminer project cgminer 4.10.0

bfgminer bfgminer 5.5.0

Vendor Advisories

Debian Bug report logs - #900929 CVE-2018-10057 CVE-2018-10058 Package: cgminer; Maintainer for cgminer is Debian Bitcoin Packaging Team <pkg-bitcoin-devel@listsaliothdebianorg>; Source for cgminer is src:cgminer (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 6 Jun 2018 21:03:01 ...