Lucene search

K
cveMitreCVE-2014-4502
HistoryJul 23, 2014 - 2:55 p.m.

CVE-2014-4502

2014-07-2314:55:06
CWE-119
mitre
web.nvd.nist.gov
23
cve-2014-4502
buffer overflows
sgminer
cgminer
bfgminer
remote pool servers
extranonc2_size
mining.subscribe
mining.notify
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

81.6%

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.

Affected configurations

Nvd
Node
bfgminerbfgminerRange4.0.0
Node
sgminer_projectsgminerRange4.2.1
OR
sgminer_projectsgminerMatch4.0.0
OR
sgminer_projectsgminerMatch4.1.0
OR
sgminer_projectsgminerMatch4.1.153
OR
sgminer_projectsgminerMatch4.1.242
OR
sgminer_projectsgminerMatch4.1.271
OR
sgminer_projectsgminerMatch4.2.0
Node
bfgminerbfgminerRange3.2.9
OR
bfgminerbfgminerMatch3.2.0
OR
bfgminerbfgminerMatch3.2.1
OR
bfgminerbfgminerMatch3.2.2
OR
bfgminerbfgminerMatch3.2.3
OR
bfgminerbfgminerMatch3.2.4
OR
bfgminerbfgminerMatch3.2.5
OR
bfgminerbfgminerMatch3.2.6
OR
bfgminerbfgminerMatch3.2.7
OR
bfgminerbfgminerMatch3.2.8
VendorProductVersionCPE
bfgminerbfgminer*cpe:2.3:a:bfgminer:bfgminer:*:*:*:*:*:*:*:*
sgminer_projectsgminer*cpe:2.3:a:sgminer_project:sgminer:*:*:*:*:*:*:*:*
sgminer_projectsgminer4.0.0cpe:2.3:a:sgminer_project:sgminer:4.0.0:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.0cpe:2.3:a:sgminer_project:sgminer:4.1.0:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.153cpe:2.3:a:sgminer_project:sgminer:4.1.153:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.242cpe:2.3:a:sgminer_project:sgminer:4.1.242:*:*:*:*:*:*:*
sgminer_projectsgminer4.1.271cpe:2.3:a:sgminer_project:sgminer:4.1.271:*:*:*:*:*:*:*
sgminer_projectsgminer4.2.0cpe:2.3:a:sgminer_project:sgminer:4.2.0:*:*:*:*:*:*:*
bfgminerbfgminer3.2.0cpe:2.3:a:bfgminer:bfgminer:3.2.0:*:*:*:*:*:*:*
bfgminerbfgminer3.2.1cpe:2.3:a:bfgminer:bfgminer:3.2.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 171

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.008

Percentile

81.6%