CVE-2018-17145
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
10/09/2020
Last modified:
15/09/2020
Description
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:bcoin:bcoin:*:*:*:*:*:*:*:* | 1.0.2 (excluding) | |
| cpe:2.3:a:bitcoin:bitcoin_core:*:*:*:*:*:*:*:* | 0.16.0 (including) | 0.16.2 (excluding) |
| cpe:2.3:a:bitcoinknots:bitcoin_knots:*:*:*:*:*:*:*:* | 0.16.0 (including) | 0.16.2 (excluding) |
| cpe:2.3:a:btcd_project:btcd:0.3.0:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.3.1:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.3.2:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.3.3:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.4.0:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.5.0:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.6.0:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.7.0:alpha:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.8.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.9.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.10.0:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:btcd_project:btcd:0.11.0:beta:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



