The miner statistics HTTP API in EWBF Cuda Zcash Miner Version 0.3.4b hangs on incoming TCP connections until some sort of request is made (such as "GET / HTTP/1.1"), which allows for a Denial of Service attack preventing a user from viewing their mining statistics by an attacker opening a session with telnet or netcat and connecting to the miner on the HTTP API port.
References
Link | Resource |
---|---|
https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970 | Issue Tracking Third Party Advisory |
https://www.legacysecuritygroup.com/cve-2017-15300.html | Third Party Advisory |
https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970 | Issue Tracking Third Party Advisory |
https://www.legacysecuritygroup.com/cve-2017-15300.html | Third Party Advisory |
Configurations
History
21 Nov 2024, 03:14
Type | Values Removed | Values Added |
---|---|---|
References | () https://bitcointalk.org/index.php?topic=1707546.msg23016970#msg23016970 - Issue Tracking, Third Party Advisory | |
References | () https://www.legacysecuritygroup.com/cve-2017-15300.html - Third Party Advisory |
Information
Published : 2017-10-15 08:29
Updated : 2025-04-20 01:37
NVD link : CVE-2017-15300
Mitre link : CVE-2017-15300
CVE.ORG link : CVE-2017-15300
JSON object : View
Products Affected
ewbf
- cuda_zcash_miner
CWE