Vulnerability Description
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cgminer Project | Cgminer | 4.10.0 |
| Bfgminer | Bfgminer | 5.5.0 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2018/06/03/1Mailing ListThird Party Advisory
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2018-10058ExploitThird Party Advisory
- http://www.openwall.com/lists/oss-security/2018/06/03/1Mailing ListThird Party Advisory
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2018-10058ExploitThird Party Advisory
FAQ
What is CVE-2018-10058?
CVE-2018-10058 is a vulnerability with a CVSS score of 8.8 (HIGH). The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-onl...
How severe is CVE-2018-10058?
CVE-2018-10058 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10058?
Check the references section above for vendor advisories and patch information. Affected products include: Cgminer Project Cgminer, Bfgminer Bfgminer.