[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: CVE-2012-2459: Critical Vulnerability, but still reserved.



On mar., 2012-07-03 at 01:15 -0500, Mike Mestnik wrote:
> Currently this(bitcoind) package is in back-ports.
> 
> I think things may have gotten mixed up, here is the publication:
> https://bitcointalk.org/index.php?topic=81749.0
> 
> Here is what the bitcoin daemon says:
> cheako@hades:~$ bitcoind getinfo
> {
>     "version" : 32400,
>     "balance" : 0.00000000,
>     "blocks" : 131724,
>     "connections" : 10,
>     "proxy" : "10.180.85.62:9050",
>     "generate" : false,
>     "genproclimit" : -1,
>     "difficulty" : 876954.49351354,
>     "hashespersec" : 0,
>     "testnet" : false,
>     "keypoololdest" : 1341291269,
>     "paytxfee" : 0.00000000,
>     "errors" : "URGENT: upgrade required, see http://bitcoin.org/dos for
> details"
> }

Well, we were just not aware of the CVE attribution (and none of the
canonical CVE sources seem to know about this either).

I'll update the tracker, but you'll need to check with backports team
for the fix.

Regards,
-- 
Yves-Alexis

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: