CVE-2015-6964

MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occurs because there is no message authentication code (MAC).
Configurations

Configuration 1 (hide)

cpe:2.3:a:multibit:multibit_hd:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:35

Type Values Removed Values Added
References () https://web.archive.org/web/20160506095434/https://multibit.org/blog/2015/07/25/bit-flipping-attack.html - Exploit, Third Party Advisory () https://web.archive.org/web/20160506095434/https://multibit.org/blog/2015/07/25/bit-flipping-attack.html - Exploit, Third Party Advisory

Information

Published : 2023-09-25 05:15

Updated : 2024-11-21 02:35


NVD link : CVE-2015-6964

Mitre link : CVE-2015-6964

CVE.ORG link : CVE-2015-6964


JSON object : View

Products Affected

multibit

  • multibit_hd
CWE
CWE-697

Incorrect Comparison