CVE-2018-17145

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
10/09/2020
Last modified:
15/09/2020

Description

Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bcoin:bcoin:*:*:*:*:*:*:*:* 1.0.2 (excluding)
cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:* 0.16.0 (including) 0.16.2 (excluding)
cpe:2.3:a:bitcoinknots:bitcoin_knots:*:*:*:*:*:*:*:* 0.16.0 (including) 0.16.2 (excluding)
cpe:2.3:a:btcd_project:btcd:0.3.0:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.3.1:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.3.2:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.3.3:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.4.0:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.5.0:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.6.0:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.7.0:alpha:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.8.0:beta:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.9.0:beta:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.10.0:beta:*:*:*:*:*:*
cpe:2.3:a:btcd_project:btcd:0.11.0:beta:*:*:*:*:*:*