Bug 2251638 (CVE-2023-37192) - CVE-2023-37192 bitcoin-core: memory manipulation leading to transaction redirection
Summary: CVE-2023-37192 bitcoin-core: memory manipulation leading to transaction redir...
Keywords:
Status: NEW
Alias: CVE-2023-37192
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2251639 2251640
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-11-27 02:49 UTC by Avinash Hanwate
Modified: 2023-11-27 02:49 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Avinash Hanwate 2023-11-27 02:49:06 UTC
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.

Comment 1 Avinash Hanwate 2023-11-27 02:49:27 UTC
Created bitcoin-core tracking bugs for this issue:

Affects: epel-all [bug 2251640]
Affects: fedora-all [bug 2251639]


Note You need to log in before you can comment on or make changes to this bug.