Bug 1149711 - (CVE-2019-15947) VUL-1: CVE-2019-15947: bitcoin: bitcoin-qt stores wallet.dat data unencrypted in memory. Upon a crash, it may dump a core file.
(CVE-2019-15947)
VUL-1: CVE-2019-15947: bitcoin: bitcoin-qt stores wallet.dat data unencrypted...
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.1
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Martin Pluskal
Security Team bot
https://smash.suse.de/issue/241836/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-09-06 08:18 UTC by Alexandros Toptsoglou
Modified: 2020-01-16 14:23 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-09-06 08:18:38 UTC
CVE-2019-15947

In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory.
Upon a crash, it may dump a core file. If a user were to mishandle a core file,
an attacker can reconstruct the user's wallet.dat file, including their private
keys, via a grep "6231 0500" command.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-15947
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15947
https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2019-15947
https://gist.github.com/oxagast/50a121b2df32186e0c48411859d5861b