Releases211
Frequency1 week 6 days
Last Release
Stars3.68K
ASIC and FPGA miner in c for bitcoin

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
= 4.10.04 MEDIUM

The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).

= 4.10.06.5 MEDIUM

The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.

= 4.3.3, = 4.3.0, <= 4.3.4, = 4.3.2, = 4.3.110 HIGH

Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.

10 HIGH

Multiple heap-based buffer overflows in the parse_notify function in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 4.1.0 allow remote pool servers to have unspecified impact via a (1) large or (2) negative value in the Extranonc2_size parameter in a mining.subscribe response and a crafted mining.notify request.

= 3.8.4, = 3.7.2, = 3.4.1, = 3.3.3, = 3.4.2, = 3.6.0, = 3.6.2, = 3.8.2, = 3.5.1, = 3.3.0, = 3.3.2, = 3.8.1, = 3.9.0, = 3.12.1, = 3.6.4, = 3.7.0, = 3.12.2, = 3.12.3, = 4.0.1, = 3.4.3, = 3.8.3, = 3.8.5, = 3.3.1, = 3.6.1, = 3.7.1, = 3.8.0, = 3.10.0, = 3.3.4, = 3.5.0, = 3.11.0, = 3.6.3, = 4.0.0, = 3.4.0, = 3.12.04.3 MEDIUM

The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message.