Lucene search

K
cveMitreCVE-2014-4501
HistoryJul 23, 2014 - 2:55 p.m.

CVE-2014-4501

2014-07-2314:55:06
CWE-119
mitre
web.nvd.nist.gov
23
cve-2014-4501
buffer overflow
sgminer
cgminer
bfgminer
remote code execution
security vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.006

Percentile

79.3%

Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.

Affected configurations

Nvd
Node
sgminer_projectsgminerRange4.2.1
OR
sgminer_projectsgminerMatch4.0.0
OR
sgminer_projectsgminerMatch4.1.0
OR
sgminer_projectsgminerMatch4.1.153
OR
sgminer_projectsgminerMatch4.1.242
OR
sgminer_projectsgminerMatch4.1.271
OR
sgminer_projectsgminerMatch4.2.0
Node
cgminer_projectcgminerRange4.3.4
OR
cgminer_projectcgminerMatch4.3.0
OR
cgminer_projectcgminerMatch4.3.1
OR
cgminer_projectcgminerMatch4.3.2
OR
cgminer_projectcgminerMatch4.3.3
Node
bfgminerbfgminerRange3.2.9
OR
bfgminerbfgminerMatch3.2.0
OR
bfgminerbfgminerMatch3.2.1
OR
bfgminerbfgminerMatch3.2.2
OR
bfgminerbfgminerMatch3.2.3
OR
bfgminerbfgminerMatch3.2.4
OR
bfgminerbfgminerMatch3.2.5
OR
bfgminerbfgminerMatch3.2.6
OR
bfgminerbfgminerMatch3.2.7
OR
bfgminerbfgminerMatch3.2.8
VendorProductVersionCPE
sgminer_projectsgminer*cpe:2.3:a:sgminer_project:sgminer:*:*:*:*:*:*:*:*
sgminer_projectsgminer4.0.0cpe:2.3:a:sgminer_project:sgminer:4.0.0:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.0cpe:2.3:a:sgminer_project:sgminer:4.1.0:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.153cpe:2.3:a:sgminer_project:sgminer:4.1.153:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.242cpe:2.3:a:sgminer_project:sgminer:4.1.242:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.271cpe:2.3:a:sgminer_project:sgminer:4.1.271:*:*:*:*:*:*:*
sgminer_projectsgminer4.2.0cpe:2.3:a:sgminer_project:sgminer:4.2.0:*:*:*:*:*:*:*
cgminer_projectcgminer*cpe:2.3:a:cgminer_project:cgminer:*:*:*:*:*:*:*:*
cgminer_projectcgminer4.3.0cpe:2.3:a:cgminer_project:cgminer:4.3.0:*:*:*:*:*:*:*
cgminer_projectcgminer4.3.1cpe:2.3:a:cgminer_project:cgminer:4.3.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 221

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.4

Confidence

Low

EPSS

0.006

Percentile

79.3%