VDB
CVE-2012-1909
CVE-2012-1909
PUBLISHED
CVSS 5 MEDIUM
The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which allows remote attackers to cause a denial of service (unspendable transaction) by leveraging the ability to create a duplicate coinbase transaction.
EPSS 1.38% · 80.7th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
1.38%
80.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| bitcoin | wxbitcoin | |
| bitcoin | bitcoin_core | 0, 0.3.5, 0.3.8 |
| n/a | n/a | * |
Timeline
- Aug 6, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- Apr 24, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Sep 7, 2023 EPSS Score
References
- https://en.bitcoin.it/wiki/BIP_0030 url
- https://github.com/sipa/bitcoin/commit/a206b0ea12eb4606b93323268fc81a4f1f952531 url
- [bitcoin-development] 20120228 Duplicate transactions vulnerability mailing-list
- https://en.bitcoin.it/wiki/CVEs url
- https://bugs.gentoo.org/show_bug.cgi?id=407793 url
- https://bitcointalk.org/index.php?topic=67738.0 url
- http://r6.ca/blog/20120206T005236Z.html url
- https://nvd.nist.gov/vuln/detail/CVE-2012-1909 advisory