Bitcoin Forum
December 14, 2024, 04:22:04 PM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Vulnerability in UPnP library used by Bitcoin Core !!  (Read 1620 times)
achow101
Staff
Legendary
*
Offline Offline

Activity: 3570
Merit: 6927


Just writing some code


View Profile WWW
October 13, 2015, 11:39:46 AM
 #21

Quote from: TALOS VULNERABILITY REPORT
A specially crafted XML response can lead to a buffer overflow on the stack resulting in remote code execution. An attacker can set up a server on the local network to trigger this vulnerability.

So the local network has to be compromised first.
And if the local network is compromised, you can be in big trouble even without this vulnerability.

I hope that I understood it right.
That is correct. If the node if on a large network like a company network, this means that someone could attack the node from during the network.

Amph
Legendary
*
Offline Offline

Activity: 3248
Merit: 1070



View Profile
October 13, 2015, 12:46:37 PM
 #22

still it does not mean anything for casual users that are not even running a full node and their client is off most of the time

it's always the same story if your desktop is safe and fresh new, you are in a safebox, the only possibility would be that virus(forgot the name) that spread through security holes in the router

also what kind of attack already happened for this vulnerability? i assume none right?
johnyj
Legendary
*
Offline Offline

Activity: 1988
Merit: 1012


Beyond Imagination


View Profile
October 13, 2015, 10:55:59 PM
 #23

"It has been verified that the vulnerability can be used to crash the application at startup by running a malicious UPnP server on the local network."  Huh

saturn643
Hero Member
*****
Offline Offline

Activity: 728
Merit: 500


View Profile
October 14, 2015, 02:03:06 AM
 #24

"It has been verified that the vulnerability can be used to crash the application at startup by running a malicious UPnP server on the local network."  Huh
A upnp server on the network can send to the node malicious data to crash Bitcoin Core.

I would like to test this, anyone have any idea how?
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!