Summarize
Please upgrade to at least Bitcoin Core More InformationMiniUPnP library versions prior to 1.9.20151008 are vulnerable to a buffer overflow in the XML parser. If UPnP is enabled, they are vulnerable. Details of the vulnerability can be found here: http://talosintel.com/reports/TALOS-2015-0035/ The vulnerability has been confirmed to target startups that run a malicious UPnP service on the local network, causing their applications to crash. This only applies to distributed executables (clients), for self-built executables UPnP is disabled by default. Bitcoin Core versions 0.10.3 through 0.11.1, and the upcoming 0.12.0, will ship with the new version of the library, but will no longer enable the feature by default. No need to be nervousThe Bitcoin Core executable has Address Space Layout Randomization (ASLR), Stack Overflow Protection (SSP), and De-Execution Stack and Heap (DEP) enabled. In other words, it is difficult to perform remote code operations or leak private keys through this vulnerability. However, it is recommended that users still need to upgrade and it is best to disable UPnP as soon as possible. Manual Port ForwardingWith UPnP turned off, your node will still connect to the other 8 peers on the Bitcoin network, receiving new blocks and transactions. However, it will not accept incoming connections from other peers unless you manually enable port forwarding on your router. If you wish to do this (it is not necessary), follow this tutorial. ---- |
<<: Will the bank card networks accept Bitcoin as a mainstream currency?
>>: Bitcoin compliance solutions provider Scorechain raises $570,000 in seed funding
1. If the Dragon Palace is low and dark in color,...
According to CryptoNinjas, Bitcoin mining giant B...
Investors continued to buy Bitcoin in the cryptoc...
"Blockchain" and "Internet of Thin...
According to the official Twitter account of Gray...
The marriage line, also known as the love line, t...
At the IEEE Security and Privacy Symposium held f...
Moles also have different shapes, some are black ...
In real life, there are many men with big noses. ...
Nowadays, a good woman is one who is beautiful, t...
It’s easy to be pessimistic about ETH right now. ...
Speaking of emotional trauma, in fact, no one wan...
Many times, we are told that we should be clear a...
What does career line mean? A man's cleavage ...
Rage Review : Three large technology companies an...