CVE-2020-12119
Ledger Live before 2.7.0 does not handle Bitcoin's Replace-By-Fee (RBF). It increases the user's balance with the value of an unconfirmed transaction as soon as it is received (before the transaction is confirmed) and does not decrease the balance when it is canceled. As a result, users are exposed to basic double spending attacks, amplified double spending attacks, and DoS attacks without user consent.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12119?
CVE-2020-12119 is rated as a high severity vulnerability due to its potential to cause significant financial discrepancies in user balances.
How do I fix CVE-2020-12119?
To fix CVE-2020-12119, users should update Ledger Live to version 2.7.0 or later, which addresses the Replace-By-Fee handling issue.
What are the risks associated with CVE-2020-12119?
The risks associated with CVE-2020-12119 include inaccurate balance reporting and the possibility of users mistakenly believing they have more funds available than they actually do.
Who is affected by CVE-2020-12119?
Users of Ledger Live versions prior to 2.7.0 are affected by CVE-2020-12119.
Why is the Replace-By-Fee (RBF) handling important in CVE-2020-12119?
Replace-By-Fee handling is important in CVE-2020-12119 because it directly impacts how unconfirmed transactions are treated, potentially leading to user financial loss.