CVE-2015-6964

MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occurs because there is no message authentication code (MAC).
Configurations

Configuration 1 (hide)

cpe:2.3:a:multibit:multibit_hd:*:*:*:*:*:*:*:*

History

26 Sep 2023, 18:26

Type Values Removed Values Added
First Time Multibit
Multibit multibit Hd
References (MISC) https://web.archive.org/web/20160506095434/https://multibit.org/blog/2015/07/25/bit-flipping-attack.html - (MISC) https://web.archive.org/web/20160506095434/https://multibit.org/blog/2015/07/25/bit-flipping-attack.html - Exploit, Third Party Advisory
CWE CWE-697
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:multibit:multibit_hd:*:*:*:*:*:*:*:*

25 Sep 2023, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-09-25 05:15

Updated : 2023-12-10 15:14


NVD link : CVE-2015-6964

Mitre link : CVE-2015-6964

CVE.ORG link : CVE-2015-6964


JSON object : View

Products Affected

multibit

  • multibit_hd
CWE
CWE-697

Incorrect Comparison