CVE-2012-4684: Bitcoin Bitcoin-Qt

High severity, CVSS 7.8. EPSS: 2.9% chance of exploitation in the next 30 days.

The alert functionality in bitcoind and Bitcoin-Qt before 0.7.0 supports different character representations of the same signature data, but relies on a hash of this signature, which allows remote attackers to cause a denial of service (resource consumption) via a valid modified signature for a circulating alert.

Affected products

  • Bitcoin Bitcoin-Qt: version 0.6.3 only
  • Bitcoin Bitcoin Core: version 0.3.4 only; version 0.3.5 only; version 0.3.8 only; version 0.3.10 only; version 0.3.11 only; version 0.3.12 only; …
  • Bitcoin Bitcoind: version 0.6.3 only
  • Bitcoin Wxbitcoin: version 0.3.4 only; version 0.3.5 only; version 0.3.8 only; version 0.3.10 only; version 0.3.11 only; version 0.4.0 only; …

Published 2013-03-12. Last modified 2026-06-16.