Vulnerability Description
In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive information about the relationship between a suspected victim's address and an IP address, aka a timing side channel.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Electriccoin | Zcashd | < 2.1.1 |
References
- https://electriccoin.co/blog/new-releases-2-1-1-and-hotfix-2-1-1-1/Release NotesVendor Advisory
- https://electriccoin.co/blog/new-releases-2-1-1-and-hotfix-2-1-1-1/Release NotesVendor Advisory
FAQ
What is CVE-2020-8807?
CVE-2020-8807 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In Electric Coin Company Zcashd before 2.1.1-1, the time offset between messages could be leveraged to obtain sensitive information about the relationship between a suspected victim's address and an I...
How severe is CVE-2020-8807?
CVE-2020-8807 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8807?
Check the references section above for vendor advisories and patch information. Affected products include: Electriccoin Zcashd.