Post
Topic
Board Crittografia e decentralizzazione
Re: Bitmessage - Alternativa decentralizzata all'email
by
(A)social
on 14/02/2018, 08:58:20 UTC
Segnalo
Quote
A RCE vulnerability was found in Bitmessage. Shut down any BM software immediately. You're fine if you don't use BM.
https://github.com/Bitmessage/PyBitmessage/commit/3a8016d31f517775d226aa8b902480f4a3a148a9#comments
Compare nelle news di questo forum.

Aggiungo:
https://bitmessage.org/wiki/Main_Page

"A remote code execution vulnerability has been spotted in use against some users running PyBitmessage v0.6.2. The cause was identified and a fix has been added and released as 0.6.3.2. If you run PyBitmessage via code, we highly recommend that you upgrade to 0.6.3.2. Alternatively you may downgrade to 0.6.1 which is unaffected. We will release binary files for Windows and macOS tomorrow (2018-02-14). In the mean time, users who use binaries should downgrade to 0.6.1 using the links below.

Bitmessage developer Peter Šurda's Bitmessage addresses are to be considered compromised.

We greatly apologize for the issue and we hope to release more information as it becomes available.
"