Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Mageia 7 MGASA-2020-0458 Moderate: Bitcoin Core Memory Flaw

mageia
Calendar Grey December 17, 2020
Dist Mageia Esm H88
Mageia has issued new bitcoin packages addressing security issues such as unencrypted wallet information and potential denial-of-service risks.
Multiple vulnerabilities have been discovered in Bitcoin

Summary

Multiple vulnerabilities have been discovered in Bitcoin.
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file. If a user were to mishandle a core file, an attacker can reconstruct the user's wallet.dat file, including their private keys, via a grep "6231 0500" command (CVE-2019-15947).
Bitcoin Core 0.20.0 allows remote denial of service (CVE-2020-14198).

References

- https://bugs.mageia.org/show_bug.cgi?id=27731

- https://security.gentoo.org/glsa/202009-18

- https://www.cve.org/CVERecord?id=CVE-2019-15947

- https://www.cve.org/CVERecord?id=CVE-2020-14198

Resolution

SRPMS

- 7/core/bitcoin-0.20.1-1.mga7

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 17 Dec 2020
URL: https://advisories.mageia.org/MGASA-2020-0458.html
Type: security
CVE: CVE-2019-15947, CVE-2020-14198

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here