[bitcoin-dev] Upcoming DOS vulnerability announcements for Bitcoin Core

Gregory Maxwell gmaxwell at gmail.com
Tue Jul 7 23:14:18 UTC 2015


On Sat, Jun 27, 2015 at 6:21 AM, Gregory Maxwell <gmaxwell at gmail.com> wrote:
> On July 7th I will be making public details of several serious denial of
> service vulnerabilities which have fixed in recent versions of Bitcoin Core,
> including CVE-2015-3641.
>
> I strongly recommend anyone running production nodes exposed to inbound
> connections from the internet upgrade to 0.10.2 as soon as possible.
>
> Upgrading older systems, especially miners, is also important due to the
> BIP66 soft-fork which is about to reach enforcing status, see also:
> http://sourceforge.net/p/bitcoin/mailman/message/34199290/


Just an update here-- I'm delaying this somewhat due to recent network
turbulance and unusual attempted DOS attack activity on relayed
infrastructure.
I've also had some requests from other cryptocurrency implementors to
use a somewhat longer horizon here.


More information about the bitcoin-dev mailing list