CVE-2012-1909
Description
The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which allows remote attackers to cause a denial of service (unspendable transaction) by leveraging the ability to create a duplicate coinbase transaction.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ if you've already worked around this in production โ publish your fix to the community-verified tier.
โ Propose a mitigation on Community โ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| bitcoin | bitcoin_core | | |
| bitcoin | bitcoin_core | 0.3.4 | |
| bitcoin | bitcoin_core | 0.3.5 | |
| bitcoin | bitcoin_core | 0.3.8 | |
| bitcoin | bitcoin_core | 0.3.10 | |
| bitcoin | bitcoin_core | 0.3.11 | |
| bitcoin | bitcoin_core | 0.3.12 | |
| bitcoin | bitcoin_core | 0.4.0 | |
| bitcoin | bitcoin_core | 0.4.1 | |
| bitcoin | wxbitcoin | | |
References
- http://r6.ca/blog/20120206T005236Z.html
- http://sourceforge.net/mailarchive/forum.php?thread_name=CAPg%2BsBhmGHnMResVxPDZdfpmWTb9uqD0RrQD7oSXBQq7oHpm8g%40mail.gmail.com&forum_name=bitcoin-development
- https://bitcointalk.org/index.php?topic=67738.0
- https://bugs.gentoo.org/show_bug.cgi?id=407793
- https://en.bitcoin.it/wiki/BIP_0030
- https://en.bitcoin.it/wiki/CVEs
- https://github.com/sipa/bitcoin/commit/a206b0ea12eb4606b93323268fc81a4f1f952531
- http://r6.ca/blog/20120206T005236Z.html
- http://sourceforge.net/mailarchive/forum.php?thread_name=CAPg%2BsBhmGHnMResVxPDZdfpmWTb9uqD0RrQD7oSXBQq7oHpm8g%40mail.gmail.com&forum_name=bitcoin-development
- https://bitcointalk.org/index.php?topic=67738.0
- https://bugs.gentoo.org/show_bug.cgi?id=407793
- https://en.bitcoin.it/wiki/BIP_0030
- https://en.bitcoin.it/wiki/CVEs
- https://github.com/sipa/bitcoin/commit/a206b0ea12eb4606b93323268fc81a4f1f952531
CWEs
CWE-16
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.