Vulnerability Description
A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the [email protected] npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Simpleledger | Slp-Validate | 1.0.0 |
Related Weaknesses (CWE)
References
- https://github.com/simpleledger/slp-validate/commit/50ad96c2798dad6b9f9a13333dd0PatchThird Party Advisory
- https://github.com/simpleledger/slp-validate/security/advisories/GHSA-wmx6-vxcf-PatchThird Party Advisory
- https://github.com/simpleledger/slp-validate/commit/50ad96c2798dad6b9f9a13333dd0PatchThird Party Advisory
- https://github.com/simpleledger/slp-validate/security/advisories/GHSA-wmx6-vxcf-PatchThird Party Advisory
FAQ
What is CVE-2019-16761?
CVE-2019-16761 is a vulnerability with a CVSS score of 5.7 (MEDIUM). A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the [email protected] npm package. An attacker could create a special...
How severe is CVE-2019-16761?
CVE-2019-16761 has been rated MEDIUM with a CVSS base score of 5.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-16761?
Check the references section above for vendor advisories and patch information. Affected products include: Simpleledger Slp-Validate.