CVE-2014-4501

critical
Published 2014-07-23 ยท Modified 2026-05-06
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
10.0

Description

Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
sgminer_projectsgminer{"endIncluding":"4.2.1"}
sgminer_projectsgminer4.0.0
sgminer_projectsgminer4.1.0
sgminer_projectsgminer4.1.153
sgminer_projectsgminer4.1.242
sgminer_projectsgminer4.1.271
sgminer_projectsgminer4.2.0
cgminer_projectcgminer{"endIncluding":"4.3.4"}
cgminer_projectcgminer4.3.0
cgminer_projectcgminer4.3.1
cgminer_projectcgminer4.3.2
cgminer_projectcgminer4.3.3
bfgminerbfgminer{"endIncluding":"3.2.9"}
bfgminerbfgminer3.2.0
bfgminerbfgminer3.2.1
bfgminerbfgminer3.2.2
bfgminerbfgminer3.2.3
bfgminerbfgminer3.2.4
bfgminerbfgminer3.2.5
bfgminerbfgminer3.2.6
bfgminerbfgminer3.2.7
bfgminerbfgminer3.2.8

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.