Skip to content

CVE-2014-4502

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.

Ver en NVD

Severidad

N/A

EPSS

Probabilidad de explotación (próx. 30 días): 0.0052 (0.5%)
Percentil: 66.7%
EPSS: 2026-05-06

Afecta

bfgminer:bfgminersgminer_project:sgminer

Descripción técnica

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.

Publicada: 23/7/2014, 14:55:06
Última modificación: 6/5/2026, 22:30:45

Referencias

InicioEventosBlogRecursosEquipo