Security Advisory

CVE-2015-6964

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-09-25 00:00:00
Last updated 2024-09-24 17:39:24
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

MultiBit HD before 0.1.2 allows attackers to conduct bit-flipping attacks that insert unspendable Bitcoin addresses into the list that MultiBit uses to send fees to the developers. (Attackers cannot realistically steal these fees for themselves.) This occurs because there is no message authentication code (MAC).