-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
A Security vulnerability to report #1675
Comments
@Al1ex Hi, thanks for the desire for safety here. If you want, you can email me and encrypt it (depending on how sensitive you feel it is).. My email address is in a lot of the btcd commits and merges. You can find my gpg key on the usual servers. |
OK |
@jcvernaleo hello, I have submit this vulnerability report to you email.please check it. |
Any update on this? What is the severity and impact? |
@xtremebeing Impact is minor. rpc related and crashes node at worst. Fixing it is on my list for the next release. |
@jcvernaleo The only OpenPGP key of yours that I see on keyservers seems to be 1024-bit DSA, which is dangerously insecure. Is there a way to report a vulnerability to you with better cryptographic security than that? |
@JeremyRand sorry for the slow reply. You are correct, that key is horribly old and more than a bit embarrassing. I'll get an updated key in the next few days and will reply to you here about it. |
Hello, I found a security vulnerabilities. I want to know how to safely submit it to the project party.Or you can contact me through TG(@RedTeamPing).
The text was updated successfully, but these errors were encountered: