Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
cgminer/sgminer/BFGMiner 基于堆的缓冲区溢出漏洞
Vulnerability Description
sgminer、cgminer和BFGMiner都是比特币挖矿软件。 cgminer, sgminer和BFGMiner中的‘parse_notify’函数中存在基于堆的缓冲区溢出漏洞。攻击者可通过mining.subscribe和mining.notify请求的Extranonc2_size参数的large或negative值利用该漏洞覆盖堆中内存。以下版本受到影响:sgminer 4.2.1及之前版本,cgminer 4.3.5之前版本和BFGMiner 4.0.0及之前版本。
CVSS Information
N/A
Vulnerability Type
N/A