CVE-2014-4503: Cgminer Project Cgminer

Medium severity, CVSS 4.3. EPSS: 1.2% chance of exploitation in the next 30 days.

The parse_notify function in util.c in sgminer before 4.2.2 and cgminer 3.3.0 through 4.0.1 allows man-in-the-middle attackers to cause a denial of service (application exit) via a crafted (1) bbversion, (2) prev_hash, (3) nbit, or (4) ntime parameter in a mining.notify action stratum message.

Affected products

  • Cgminer Project Cgminer: version 3.3.0 only; version 3.3.1 only; version 3.3.2 only; version 3.3.3 only; version 3.3.4 only; version 3.4.0 only; …
  • Sgminer Project Sgminer: up to and including 4.2.1; version 4.0.0 only; version 4.1.0 only; version 4.1.153 only; version 4.1.242 only; version 4.1.271 only; …

Published 2014-07-23. Last modified 2026-06-17.