CVE-2013-3220: Bitcoin Bitcoin-Qt

Medium severity, CVSS 6.4. EPSS: 2.4% chance of exploitation in the next 30 days.

bitcoind and Bitcoin-Qt before 0.4.9rc2, 0.5.x before 0.5.8rc2, 0.6.x before 0.6.5rc2, and 0.7.x before 0.7.3rc2, and wxBitcoin, do not properly consider whether a block's size could require an excessive number of database locks, which allows remote attackers to cause a denial of service (split) and enable certain double-spending capabilities via a large block that triggers incorrect Berkeley DB locking.

Affected products

  • Bitcoin Bitcoin-Qt: up to and including 0.4.9; version 0.4 only; version 0.4.8 only; version 0.5.0 only; version 0.5.0.4 only; version 0.5.1 only; …
  • Bitcoin Bitcoin Core: any version; version 0.3.4 only; version 0.3.5 only; version 0.3.8 only; version 0.3.10 only; version 0.3.11 only; …
  • Bitcoin Bitcoind: up to and including 0.4.9; version 0.4.4 only; version 0.5.7 only; version 0.5.8 only; version 0.6.0.0 only; version 0.6.0.10 only; …
  • Bitcoin Qitcoin-Qt: version 0.6.4 only; version 0.6.5 only

Published 2013-08-02. Last modified 2026-06-16.