5
CVSSv2

CVE-2019-15947

Published: 05/09/2019 Updated: 03/05/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 446
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their private keys, via a grep "6231 0500" command.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

bitcoin bitcoin core 0.18.0

Vendor Advisories

Debian Bug report logs - #939608 bitcoin: CVE-2019-15947 Package: src:bitcoin; Maintainer for src:bitcoin is Debian Cryptocoin Team <team+cryptocoin@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 6 Sep 2019 19:21:05 UTC Severity: grave Tags: security, upstream Found in version ...