CVE-2013-3220
Severity CVSS v4.0:
Pending analysis
Type:
CWE-399
Resource Management Errors
Publication date:
02/08/2013
Last modified:
11/04/2025
Description
bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly consider whether a block's size could require an excessive number of database locks, which allows remote attackers to cause a denial of service (split) and enable certain double-spending capabilities via a large block that triggers incorrect Berkeley DB locking.
Impact
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:bitcoin:bitcoin-qt:*:rc1:*:*:*:*:*:* | 0.4.9 (including) | |
cpe:2.3:a:bitcoin:bitcoin-qt:0.4:rc4:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.4.8:rc4:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.5.0:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.5.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.5.1:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.5.3.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.5.7:*:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.5.8:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.6.0.10:rc4:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.6.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.7.0:rc1:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.7.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.7.2:*:*:*:*:*:*:* | ||
cpe:2.3:a:bitcoin:bitcoin-qt:0.7.3:rc1:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page