Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Ledger Bitcoin App 2.1.0 Address Derivation Error via Miniscript
Vulnerability Description
Ledger Bitcoin app versions 2.1.0 and 2.1.1 contain an address derivation vulnerability that allows attackers to cause incorrect Bitcoin addresses to be displayed by exploiting improper handling of miniscript policies containing the a: fragment. Attackers can craft malicious miniscript policies that cause the device to derive and display incorrect receiving addresses, potentially leading to funds being sent to unintended addresses.
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Vulnerability Type
数值计算不正确
Vulnerability Title
Ledger Bitcoin app 安全漏洞
Vulnerability Description
Ledger Bitcoin app是Ledger开源的一款运行在Ledger硬件钱包上的比特币资产管理应用。 Ledger Bitcoin app 2.1.0版本和2.1.1版本存在安全漏洞,该漏洞源于对包含a:片段的miniscript策略处理不当,可能导致攻击者利用特制的miniscript策略使设备派生并显示错误的接收地址,从而导致资金发送到意外地址。
CVSS Information
N/A
Vulnerability Type
N/A