Vulnerability Description
wxBitcoin and bitcoind before 0.3.13 do not properly handle bitcoins associated with Bitcoin transactions that have zero confirmations, which allows remote attackers to cause a denial of service (invalid-transaction flood) by sending low-valued transactions without transaction fees.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitcoin | Bitcoin Core | <= 0.3.12 |
| Bitcoin | Wxbitcoin | <= 0.3.12 |
Related Weaknesses (CWE)
References
- http://www.bitcoin.org/smf/index.php?topic=1306.0
- https://en.bitcoin.it/wiki/CVEsVendor Advisory
- http://www.bitcoin.org/smf/index.php?topic=1306.0
- https://en.bitcoin.it/wiki/CVEsVendor Advisory
FAQ
What is CVE-2010-5140?
CVE-2010-5140 is a vulnerability with a CVSS score of 5.0 (MEDIUM). wxBitcoin and bitcoind before 0.3.13 do not properly handle bitcoins associated with Bitcoin transactions that have zero confirmations, which allows remote attackers to cause a denial of service (inva...
How severe is CVE-2010-5140?
CVE-2010-5140 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2010-5140?
Check the references section above for vendor advisories and patch information. Affected products include: Bitcoin Bitcoin Core, Bitcoin Wxbitcoin.