CVE-2017-20180
Last modified
CVE-2017-20180 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinSpend of the file CoinSpend.cpp of the component Proof Handler. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the function CoinSpend::CoinSpend of the file CoinSpend.cpp of the component Proof Handler. The manipulation leads to insufficient verification of data authenticity. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as ce103a09ec079d0a0ed95475992348bed6e860de. It is recommended to apply a patch to fix this issue. VDB-222318 is the identifier assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zerocoin | Libzerocoin | < 2017-11-15 |
References
- https://vuldb.com/?ctiid.222318Permissions Required, Third Party Advisory
- https://vuldb.com/?id.222318Third Party Advisory
- https://vuldb.com/?ctiid.222318Permissions Required, Third Party Advisory
- https://vuldb.com/?id.222318Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-20180?
How severe is CVE-2017-20180?
How do I fix CVE-2017-20180?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-20175A vulnerability classified as problematic has been found in …6.1
- CVE-2017-20176A vulnerability classified as problematic was found in ciubo…6.1
- CVE-2017-20177A vulnerability, which was classified as problematic, has be…6.1
- CVE-2017-20178** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in…7.5
- CVE-2017-20179A vulnerability was found in InSTEDD Pollit 2.3.1. It has be…9.8
- CVE-2017-2018Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2017-20181A vulnerability classified as critical was found in hgzojer …5.5
- CVE-2017-20182A vulnerability was found in Mobile Vikings Django AJAX Util…6.1
- CVE-2017-20183A vulnerability was found in External Media without Import P…6.1
- CVE-2017-20184Improper Limitation of a Pathname to a Restricted Directory …7.5
- CVE-2017-20185** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in…6.1
- CVE-2017-20186** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in…7.5
Are you affected by CVE-2017-20180?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
