Are v0.17rc1-v0.17rc3 affected by CVE-2018-17144? If yes, I think CVE-2018-17144 should be updated. Anyway v0.17rc4 was merged in https://github.com/bitcoin/bitcoin/commit/c64128df5882e8dc1f76ae7c1e998ed57b8645fe with #14247 Thanks
Are v0.17rc1-v0.17rc3 affected by CVE-2018-17144? #14323
issue isghe opened this issue on September 25, 2018-
isghe commented at 9:01 PM on September 25, 2018: contributor
-
MarcoFalke commented at 11:12 PM on September 25, 2018: member
The wiki is unrelated to Bitcoin Core and can be edited by anyone with an account.
- MarcoFalke closed this on Sep 25, 2018
-
isghe commented at 12:10 AM on September 26, 2018: contributor
Thanks for your feedback.
I am sorry but, It's not so simple as you described in your reply: having an account in it's wiki it's not enough to have the power to edit wiki pages.
<img width="885" alt="screen shot 2018-09-26 at 01 34 27" src="https://user-images.githubusercontent.com/1006078/46049195-5ba48d80-c12d-11e8-9ce4-2ec3f8941d66.png">
And the activation procedure is: <img width="519" alt="screen shot 2018-09-26 at 01 33 43" src="https://user-images.githubusercontent.com/1006078/46049314-ee452c80-c12d-11e8-8f80-12e2d7ffc9f1.png">
I also replied to an email asking to me to, activate my account on bitcoin-wiki:
I wrote this 23 September 2018 in IRG#bitcoin-wiki:
"Hi, I think in https://en.bitcoin.it/wiki/Common_Vulnerabilities_and_Exposures#CVE-2018-17144 we should add in affected versions: "0.17.0rc1 - 0.17.0rc3" and fix version "0.17.0rc4", thanks :-)"
And I wrote exactly the same message again in the same IRG#bitcoin-wiki few hours ago, with the same result: ignored.
<img width="1423" alt="screen shot 2018-09-26 at 01 53 22" src="https://user-images.githubusercontent.com/1006078/46049506-1d0fd280-c12f-11e8-94bc-6ea45d2ad031.png">
And the subject question still remains opened: Are v0.17rc1-v0.17rc3 affected by CVE-2018-17144?
Thanks, Isidoro
-
achow101 commented at 12:12 AM on September 26, 2018: member
Issues concerning the wiki are unrelated to this project.
Are v0.17rc1-v0.17rc3 affected by CVE-2018-17144?
Yes, but they are also no longer available for download.
- DrahtBot locked this on Sep 8, 2021