Back to search
CVE-2016-10724
Published: Jul 5, 2018
Modified: Aug 6, 2024
PUBLISHED
Description
Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2016) if an attacker can sign a message with a certain private key that had been known by unintended actors, because of an infinitely sized map. This affects other uses of the codebase, such as Bitcoin Knots before v0.13.0.knots20160814 and many altcoins.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures
x_refsource_MISC
https://github.com/JinBean/CVE-Extension
x_refsource_MISC
https://bitcoin.org/en/posts/alert-key-and-vulnerabilities-disclosure
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now