CVE-2015-20111

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Nov 18, 2024
CWE ID 120

Summary

CVE-2015-20111 is a vulnerability affecting miniupnp before version 4c90b87, which was used in Bitcoin Core prior to 0.12 and other products. This issue stems from insufficient checks on snprintf return values, resulting in a buffer overflow and substantial data leak. This is distinct from CVE-2019-12107. In the context of Bitcoin Core before 0.12, an attacker could potentially carry out remote code execution when exploiting CVE-2015-6031.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share