Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 431428 (CVE-2012-3789) - <net-p2p/bitcoind-0.6.3, <net-p2p/bitcoin-qt-0.6.3: DoS vulnerability (CVE-2012-3789)
Summary: <net-p2p/bitcoind-0.6.3, <net-p2p/bitcoin-qt-0.6.3: DoS vulnerability (CVE-20...
Status: RESOLVED FIXED
Alias: CVE-2012-3789
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: http://nvd.nist.gov/nvd.cfm?cvename=C...
Whiteboard: B3 [noglsa]
Keywords:
Depends on: 429188
Blocks:
  Show dependency tree
 
Reported: 2012-08-14 20:48 UTC by GLSAMaker/CVETool Bot
Modified: 2012-12-11 17:38 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2012-08-14 20:48:06 UTC
CVE-2012-3789 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-3789):
  Unspecified vulnerability in bitcoind and Bitcoin-Qt before 0.4.7rc3, 0.5.x
  before 0.5.6rc3, 0.6.0.x before 0.6.0.9rc1, and 0.6.x before 0.6.3rc1 allows
  remote attackers to cause a denial of service (process hang) via unknown
  behavior on a Bitcoin network.


Maintainers, please bump.
Comment 1 Sean Amoss (RETIRED) gentoo-dev Security 2012-09-16 15:34:37 UTC
From upstream release notes [1]:

Bitcoin version 0.6.3 is now available for download at:
  http://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.3/

This is a bug-fix release, with no new features.

CHANGE SUMMARY
==============

Fixed a serious denial-of-service attack that could cause the
bitcoin process to become unresponsive. Thanks to Sergio Lerner
for finding and responsibly reporting the problem. (CVE-2012-3789)


[1] http://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.3/

Stabilization of =net-p2p/bitcoin-qt-0.6.3 and =net-p2p/bitcoind-0.6.3 is in bug 429188.
Comment 2 Sean Amoss (RETIRED) gentoo-dev Security 2012-10-21 02:04:38 UTC
GLSA vote: no.
Comment 3 Tim Sammut (RETIRED) gentoo-dev 2012-12-11 17:38:43 UTC
Thanks, folks. GLSA Vote: no. Closing noglsa.