7.8
CVSSv3

CVE-2018-6353

Published: 27/01/2018 Updated: 15/02/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The Python console in Electrum up to and including 2.9.4 and 3.x up to and including 3.0.5 supports arbitrary Python code without considering (1) social-engineering attacks in which a user pastes code that they do not understand and (2) code pasted by a physically proximate attacker at an unattended workstation, which makes it easier for malicious users to steal Bitcoin via hook code that runs at a later time when the wallet password has been entered, a different vulnerability than CVE-2018-1000022.

Vulnerable Product Search on Vulmon Subscribe to Product

electrum electrum 3.0.3

electrum electrum

electrum electrum 3.0.5

electrum electrum 3.0.0

electrum electrum 3.0.1

electrum electrum 3.0.2

Vendor Advisories

Debian Bug report logs - #890003 electrum: CVE-2018-6353 Package: src:electrum; Maintainer for src:electrum is Tristan Seligmann <mithrandi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 9 Feb 2018 21:51:02 UTC Severity: minor Tags: fixed-upstream, security, upstream Found in version ...