mirror of
https://github.com/seigler/dash-docs
synced 2025-07-28 18:26:13 +00:00
Add "Network status and alerts" page and RSS feed (fixes #170)
Generate alerts pages through alerts.rb plugin Allow to keep short alias urls for each alert Move alert pages in _alerts Update sitemap plugin to include alerts
This commit is contained in:
parent
cd597fdb21
commit
ec44853934
18 changed files with 385 additions and 54 deletions
36
_alerts/2012-02-18-protocol-change.html
Normal file
36
_alerts/2012-02-18-protocol-change.html
Normal file
|
@ -0,0 +1,36 @@
|
|||
---
|
||||
title: "February 20, 2012 Protocol Changes"
|
||||
lastmod: "Mon Feb 20 00:10:00 UTC 2012"
|
||||
alias: "feb20"
|
||||
active: false
|
||||
---
|
||||
<p>
|
||||
In June 2010 the Bitcoin reference software version 0.2.10 introduced
|
||||
a change to the protocol: the 'version' messages exchanged by nodes
|
||||
at connection time would have a new format that included checksum
|
||||
values to detect corruption by broken networks.
|
||||
</p><p>
|
||||
All other messages already carry a checksum (for connections between
|
||||
nodes 0.2.9 and later) but the version messages themselves could not
|
||||
be changed in a compatible way, so this change was delayed and did not take effect until
|
||||
<a href="http://www.timeanddate.com/worldclock/fixedtime.html?msg=Bitcoin+protocol+change&iso=20120220T00">midnight UTC on Feb 20th 2012</a>
|
||||
to leave users time to upgrade.
|
||||
</p><p>
|
||||
The developers of the Bitcoin reference software are unable to find
|
||||
any evidence of any nodes still running software prior to 0.2.10 on
|
||||
the network. If any nodes with software this old
|
||||
do still exist, they will no longer be able to connect to newer nodes.
|
||||
</p><p>
|
||||
This switchover has been tested and no significant disruption is
|
||||
expected and none has been observed so far.
|
||||
Nodes with incorrect clocks may have a difficult
|
||||
time making new connections for a brief period around the switchover
|
||||
time.
|
||||
</p><p>
|
||||
Please report any new connectivity issues to the <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">#bitcoin-dev
|
||||
channel</a> on Freenode IRC.
|
||||
</p><p>
|
||||
If there are unexpected difficulties this page will be updated with
|
||||
relevant information.
|
||||
</p>
|
227
_alerts/2012-03-16-critical-vulnerability.html
Normal file
227
_alerts/2012-03-16-critical-vulnerability.html
Normal file
|
@ -0,0 +1,227 @@
|
|||
---
|
||||
title: "Potentially Critical Security Vulnerability"
|
||||
lastmod: "Fri Mar 16 22:58:00 UTC 2012"
|
||||
alias: "critfix"
|
||||
active: false
|
||||
---
|
||||
<p>
|
||||
A potential security vulnerability has been discovered in the Windows
|
||||
version of Bitcoin-Qt. If you are running Bitcoin-Qt versions 0.5
|
||||
through 0.6 on Windows you should shut it down and upgrade to either
|
||||
version 0.5.3.1 or 0.6rc4 NOW.
|
||||
</p><p>
|
||||
The command-line bitcoin daemon (bitcoind), Mac and Linux versions of
|
||||
Bitcoin-Qt, and versions prior to 0.5 are not affected.
|
||||
</p><p>
|
||||
Due to the nature of the vulnerability, we believe it would be very
|
||||
difficult for an attacker to do anything more than crash the
|
||||
Bitcoin-Qt process. However, because there is a possibility of such a
|
||||
crash causing remote code execution we consider this a critical issue.
|
||||
</p><p>
|
||||
If you have any questions, feel free to drop by <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">
|
||||
the #bitcoin-dev channel</a> on Freenode IRC.
|
||||
</p><p>
|
||||
You can download updated binaries from SourceForge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 for Windows and 0.5.3 for Linux</a>
|
||||
</p>
|
||||
|
||||
<h3>Español: Vulnerabilidad de seguridad (potencialmente crítica)</h3>
|
||||
<p>
|
||||
Una vulnerabilidad de seguridad posible no son afectadas en la versión Windows de Bitcoin-Qt. Si está utilizando Bitcoin-Qt 0.5 a través de las versiones 0.6 en Windows, debe cerrar y actualizar a la versión 0.5.3.1 o 0.6rc4 AHORA.
|
||||
</p><p>
|
||||
El daemon de la línea de comandos (bitcoind), las versiones Mac y Linux de Bitcoin-Qt, y las versiones anteriores a 0.5 no son afectadas.
|
||||
</p><p>
|
||||
Debido a la naturaleza de la vulnerabilidad, creemos que sería muy difícil para un atacante para hacer algo más que chocar Bitcoin-Qt. Sin embargo, debido a que existe la posibilidad causaría la ejecución remota de código consideramos este un tema crítico.
|
||||
</p><p>
|
||||
Si tiene alguna pregunta, venga al canal <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">#bitcoin-dev</a> en Freenode.
|
||||
</p><p>
|
||||
Puede descargar los archivos binarios actualizados desde SourceForge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6rc</a><br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 para Windows y 0.5.3 para Linux</a>
|
||||
</p>
|
||||
|
||||
<h3>Deutsch: DRINGEND: Windows Bitcoin-Qt update</h3>
|
||||
<p>
|
||||
Es wurde eine potenzielle Schwachstelle in der Windowsversion Qt-Bitcoin entdeckt. Wenn Sie mit Bitcoin-Qt-Versionen 0.5 bis 0.6 unter Windows arbeiten, sollten Sie das Programm beenden und ein Upgrade auf entweder Version 0.5.3.1 oder 0.6rc4 JETZT durchführen.
|
||||
</p><p>
|
||||
Der Kommandozeilen-Bitcoin Daemon (bitcoind), Mac-und Linux-Versionen Bitcoin-Qt-Versionen vor und 0.5 sind nicht betroffen.
|
||||
</p><p>
|
||||
Aufgrund der Art der Schwachstelle glauben wir, das es sehr schwer wäre mehr als einen Absturz des Bitcoin-Qt Prozesses zu bewirken.
|
||||
Nachdem jedoch eine theoretische Möglichkeit eine "Remote Code Execution" besteht erachten wir das als einen kritischen Fall.
|
||||
</p><p>
|
||||
Wenn Sie noch Fragen haben, kommen sie in <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">
|
||||
#bitcoin-dev Kanal</a> auf FreeNode IRC.
|
||||
</p><p>
|
||||
Binärdateien sind auf SourceForge verfügbar:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 für Windows und 0.5.3 für Linux</a>
|
||||
</p>
|
||||
|
||||
<h3>Nederlands: Mogelijk kritisch veiligheidsprobleem</h3>
|
||||
<p>
|
||||
Er is een een mogelijk veiligheidsprobleem gevonden in de Windows versie van
|
||||
Bitcoin-Qt. Als u Bitcoin-Qt versie 0.5 tot 0.6 draait, sluit het dan af
|
||||
en upgrade naar versie 0.5.3.1 of 0.6rc4 NU.
|
||||
</p><p>
|
||||
De commandolijn bitcoin daemon (bitcoind), en de Mac of de Linux versie van
|
||||
Bitcoin-Qt en versie voor 0.5 zijn niet kwetsbaar.
|
||||
</p><p>
|
||||
Omwille van het soort veiligheidsprobleem geloven wij dat het zeer
|
||||
moeilijk zou zijn voor een aanvaller om iets anders te doen dan het
|
||||
Bitcoin-Qt proces te doen crashen. Echter, aangezien er een mogelijkheid
|
||||
is tot het uitvoering van code, beschouwen we dit als
|
||||
een kritisch probleem.
|
||||
</p><p>
|
||||
Indien u enige vragen heeft, kom gerust langs op het <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">
|
||||
het #bitcoin-dev kanaal</a> op Freenode IRC.
|
||||
</p><p>
|
||||
U kan een aangepaste versie downloaden op SourceForge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 voor Windows en 0.5.3 for Linux</a>
|
||||
</p>
|
||||
|
||||
<h3>Русский: Найдена потенциальная критическая уязвимость в версиях Bitcoin-Qt от 0.5 до 0.6 для Windows</h3>
|
||||
<p>
|
||||
Найдена потенциальная критическая уязвимость в версиях Bitcoin-Qt от 0.5 до 0.6 для Windows. Если вы используете одну из этих версий, отключите её и обновитесь до 0.5.3.1 или 0.6rc4 немедленно.
|
||||
</p><p>
|
||||
Версия для командной строки, версии до 0.5, а также версии для Linux и MacOS не подвержены этой уязвимости.
|
||||
</p><p>
|
||||
Из-за сути проблемы мы считаем что злоумышленнику будет сложно сделать что-либо помимо завершения процесса Bitcoin-Qt с ошибкой, но поскольку есть теоретическая вероятность что это может вызвать удалённое выполнение кода, мы считаем эту уязвимость критической.
|
||||
</p><p>
|
||||
Если у вас есть какие-либо вопросы, обращайтесь на канал <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">
|
||||
#bitcoin-dev</a> сети Freenode.
|
||||
</p><p>
|
||||
Вы можете скачать обновлённые выполняемые файлы с SourceForge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 RC</a><br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1</a>
|
||||
</p>
|
||||
|
||||
<h3>Italiano: Potenziale vulnerabilità di sicurezza critica.</h3>
|
||||
<p>
|
||||
Una potenziale vulnerabilità di sicurezza è stata scoperta nella versione di Windows di Bitcoin-Qt. Se stai usando Bitcoin-Qt su Windows dalle versioni 0.5 alla 0.6 dovresti chiuderla e aggiornarla alle versioni 0.5.3.1 o 0.6rc4 ORA.
|
||||
</p><p>
|
||||
La versione di Bitcoin a linea di comando (bitcoind), le versioni Mac e Linux di Bitcoin-Qt, e le versioni precedenti alla 0.5 non sono affette dal problema.
|
||||
</p><p>
|
||||
Vista la natura della vulnerabilità, crediamo sia molto difficile che un attacco posso fare niente di più del crashare il processo Bitcoin-Qt. Tutta via, visto che c'è la possibilità che questo crash possa causare l'esecuzione di codice remoto lo consideriamo come critico.
|
||||
</p><p>
|
||||
Per qualunque domanda, sentitevi liberi di venire <a href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">sul canale #bitcoin-dev</a> su Freenode IRC.
|
||||
</p><p>
|
||||
Potete scaricare le versioni aggiornate da SourceForge: <br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidate</a><br><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.2 per Windows e 0.5.3 per Linux</a>
|
||||
</p>
|
||||
|
||||
<h3>Português: Vulnerabilidade de segurança potencialmente crítica</h3>
|
||||
<p>
|
||||
Uma vulnerabilidade de segurança em potencial foi descoberto na versão do Bitcoin-Qt para Windows. Se você estiver executando alguma versão entre a 0.5 até a 0.6 do Bitcoin-Qt no Windows, você deve desligá-lo e atualizá-lo para a versão 0.5.3.1 ou 0.6rc4 AGORA!
|
||||
</p><p>
|
||||
A versão em linha de comando do Bitcoin (bitcoin daemon - bitcoind), as versões para Mac e Linux do Bitcoin-Qt, e versões anteriores a 0.5 não são afetadas.
|
||||
</p><p>
|
||||
Devido à natureza da vulnerabilidade, acreditamos que seria muito difícil para um atacante conseguir fazer qualquer coisa além de travar o programa Bitcoin-Qt. No entanto, como há uma possibilidade de tal acidente causar uma execução de código remota, nós consideramos esta uma questão crucial.
|
||||
</p><p>
|
||||
Se você tem qualquer questionamento, sinta-se livre para entrar no canal <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">
|
||||
#bitcoin-dev</a> no servidor IRC em Freenode.
|
||||
</p><p>
|
||||
Você poderá instalar os novos binários a partir do SourceForge:<br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 para Windows e 0.5.3 para Linux</a>
|
||||
</p><p>
|
||||
Traduzido por Thiago Martins (ThiagoCMC)
|
||||
</p>
|
||||
|
||||
<h3>Polski: Potencjalnie Krytyczne Zagrozenie Bezpieczenstwa</h3>
|
||||
<p>
|
||||
Potencjalne zagrozenie zostalo odkryte w Bitcoin-QT wersji Windows. Jesli masz uruchomiony Bitcoin-Qt w wersjach 0.5 przez 0.6 w wersji Windows powinienes je zamknac i pobrac najnowsze wersje 0.5.3.1 lub 0.6rc4 TERAZ.
|
||||
</p><p>
|
||||
Demon bitcoin z linni polecen(bitcoind), wersje MAC i Linux Bitcoin-QT, i wersje ponizej 0.5 nie sa zagrozone.
|
||||
</p><p>
|
||||
Z wzgeldu na nature zagrozenia, wierzymy ze osoba atakujaca miala by spory problem z zrobieniem czego kolwiek innego niz zawieszenie procesu Bitcoin-QT. Jednak, jest mozliwosc ze takie zawieszenie procesu moglo by doprowadzic do zdalenego odpalenia kodu uwazamy je za krytyczne.
|
||||
</p><p>
|
||||
Jesli masz jakie kolwiek pytania kieruj je na kanal <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">#bitcoin-dev</a> IRC Freenode.
|
||||
</p><p>
|
||||
Mozesz sciagnac zrodlo z SourceForge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 dla WIndows i 0.5.3 dla Linuxa</a>
|
||||
</p>
|
||||
|
||||
<h3>Български език: Уязвимост в сигурността.</h3>
|
||||
<p>
|
||||
Уязвимост в сигурността бе открита при Windows версията на Bitcoin-Qt.Ако използвате Bitcoin-Qt версия 0.5 до 0.6 през Windows,ще се наложи да я спрете и да направите ъпгрейд до 0.5.3.1 или 0.rc4.Command-line даемон-а(bitcoind),няма да бъде афектиран за потребители на Mac или Linux.Поради вида на тази уязвимост,ние вярваме,че би могло да бъде доста трудно за атакуващия да направи нещо повече от това да crash-не процесът - Bitcoin-Qt.Поради това ние го считаме за критичен проблем.
|
||||
</p><p>
|
||||
Ако имате някъкви въпроси,не се притеснявайте да ги зададете в <a
|
||||
href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">
|
||||
#Bitcoin-dev @freenode</a>.
|
||||
</p><p>
|
||||
Можете да изтеглите ъпдейтите от Sourceforge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br /><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 за Windows и 0.5.3 за Linux.</a>
|
||||
</p>
|
||||
|
||||
<h3>Ελληνικά: Σοβαρό πρόβλημα ασφάλειας</h3>
|
||||
<p>
|
||||
Ένα πιθανά σοβαρό πρόβλημα ασφάλειας εντοπίστηκε στην έκδοση Windows του Bitcoin-Qt. Εαν χρησιμοποιείτε Bitcoin-Qt εκδόσεις 0.5 έως 0.6 στα Windows, αναβαθμήστε <b>άμεσα</b> σε έκδοση 0.5.3.1 ή 0.6rc4.
|
||||
</p><p>
|
||||
Ο δαίμονας bitcoind, οι εκδόσεις Mac, Linux του bitcoin-Qt, και εκδόσεις παλαιότερες της 0.5 δεν επηρεάζονται απο το πρόβλημα.
|
||||
</p><p>
|
||||
Λόγω της φύσης του προβλήματος, πιστεύουμε οτι είναι σχεδόν απίθανο κάποιος εισβολέας να καταφέρει οτιδήποτε περισσότερο απο το να κλείσει το Bitcoin-Qt. Παρ'όλα αυτά, επειδή κάτι τέτοιο θα μπορούσε να οδηγήσει σε απομακρυσμένη εκτέλεση κώδικα, θεωρούμε το συγκεκριμένο πρόβλημα πολύ σοβαρό.
|
||||
</p><p>
|
||||
Για οποιαδήποτε απορία μπορείτε να επισκευθείτε το κανάλι <a href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">#bitcoin-dev</a> στο IRC (Freenode).
|
||||
</p><p>
|
||||
Μπορείτε να κατεβάσετε νέες εκδόσεις απο το SourceForge:<br />
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 για Windows και 0.5.3 για Linux</a>
|
||||
</p>
|
||||
|
||||
<h3>Svenska: Potentiellt kritiskt säkerhetshål</h3>
|
||||
<p>
|
||||
Ett potentiellt kritiskt säkerhetshål har upptäckts i Windowsversionen av Bitcoin-QT. Om du kör Bitcoin-QT i någon av versionerna 0.5 t.o.m. 0.6 för Windows så bör du stänga av programmet och uppgradera till version 0.5.3.1 eller 0.6rc4 OMGÅENDE.
|
||||
</p><p>
|
||||
Kommandoradsprogrammet Bitcoin daemon (bitcoind), Mac- och Linuxversionerna av Bitcoin-QT samt tidigare versioner än 0.5 påverkas ej.
|
||||
</p><p>
|
||||
P.g.a. den typ av sårbarhet det handlar om tror vi att det skulle vara mycket svårt för en angripare att göra något att än att krascha Bitcoin-QT-processen, men eftersom det finns en risk att en sådan krasch kan orsaka "remote code execution" betraktar vi detta som ett kritiskt säkerhetshål.
|
||||
</p><p>
|
||||
Om du har några frågor är du välkommen in på kanalen <a href="http://webchat.freenode.net/?channels=bitcoin-dev&uio=d4">#bitcoin-dev</a> på Freenode IRC.
|
||||
</p><p>
|
||||
Du kan ladda ner uppdaterade binärer från SourceForge:<br/>
|
||||
<a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.0/test/">
|
||||
0.6 Release Candidates</a><br><a
|
||||
href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.5.3/">
|
||||
0.5.3.1 för Windows och 0.5.3 för Linux</a>
|
||||
</p>
|
61
_alerts/2012-05-14-dos.html
Normal file
61
_alerts/2012-05-14-dos.html
Normal file
|
@ -0,0 +1,61 @@
|
|||
---
|
||||
title: "CVE-2012-2459: Critical Vulnerability (denial-of-service)"
|
||||
lastmod: "Mon May 14 17:00:00 UTC 2012"
|
||||
alias: "dos"
|
||||
active: false
|
||||
---
|
||||
<h2>Risks</h2>
|
||||
<p>
|
||||
A denial-of-service vulnerability that affects all versions of
|
||||
bitcoind and Bitcoin-Qt has been reported and fixed. An attacker
|
||||
could isolate a victim's node and cause the creation of blockchain
|
||||
forks.
|
||||
</p>
|
||||
<h2>Solutions</h2>
|
||||
<p>
|
||||
Because this bug could be exploited to severely disrupt the Bitcoin
|
||||
network we consider this a critical vulnerability, and encourage
|
||||
everybody to upgrade to <a href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.6.2/">the latest version: 0.6.2</a>.
|
||||
</p>
|
||||
<p>
|
||||
<a href="https://bitcointalk.org/?topic=79651">Backports for older releases (0.5.5 and 0.4.6) are also available</a> if
|
||||
you cannot upgrade to version 0.6.2.
|
||||
</p>
|
||||
<h2>Technical Details</h2>
|
||||
<p>
|
||||
Full technical details are being withheld to give people the
|
||||
opportunity to upgrade.
|
||||
</p>
|
||||
<p>
|
||||
Thanks to <a href="http://forre.st/">Forrest Voight</a> for discovering and reporting the vulnerability.
|
||||
</p>
|
||||
<h2>Questions & Answers</h2>
|
||||
<h3>
|
||||
How would I know if I am the victim of this attack?
|
||||
</h3>
|
||||
<p>
|
||||
Your bitcoin process would stop processing blocks and would have a
|
||||
different block count from the rest of the network (you can see the
|
||||
current block count at websites like <a href="http://blockexplorer.com/">blockexplorer.com</a> or
|
||||
<a href="http://blockchain.info/">blockchain.info</a>). Eventually it would display the message:
|
||||
</p>
|
||||
<blockquote>WARNING: Displayed transactions may not be correct! You may need to
|
||||
upgrade, or other nodes may need to upgrade.</blockquote>
|
||||
<p>
|
||||
(note that this message is displayed whenever your bitcoin process
|
||||
detects that the rest of the network seems to have a different
|
||||
block count, which can happen for several reasons unrelated to
|
||||
this vulnerability).
|
||||
</p>
|
||||
<h3>
|
||||
Could this bug be used to steal my wallet?
|
||||
</h3>
|
||||
<p>
|
||||
No.
|
||||
</p>
|
||||
<h3>
|
||||
Could this bug be used to install malware on my system?
|
||||
</h3>
|
||||
<p>
|
||||
No.
|
||||
</p>
|
37
_alerts/2013-03-11-chain-fork.html
Normal file
37
_alerts/2013-03-11-chain-fork.html
Normal file
|
@ -0,0 +1,37 @@
|
|||
---
|
||||
title: "11/12 March 2013 Chain Fork Information"
|
||||
lastmod: "16 May 2013 01:37 UTC"
|
||||
alias: "chainfork"
|
||||
active: false
|
||||
---
|
||||
<h2>What happened</h2>
|
||||
<p>
|
||||
A bitcoin miner running version 0.8.0 created a large block (at height 225,430) that is incompatible
|
||||
with earlier versions of Bitcoin.
|
||||
</p>
|
||||
<p>
|
||||
The result was a block chain fork, with miners, merchants and users running the new version of bitcoin
|
||||
accepting, and building on, that block, and miners, merchants and users running older versions of bitcoin
|
||||
rejecting it and creating their own block chain.
|
||||
</p>
|
||||
<h2>What is being done</h2>
|
||||
<p>
|
||||
Large mining pools running version 0.8.0 were asked to switch back to version 0.7, to create a
|
||||
single block chain compatible with all bitcoin software.
|
||||
</p>
|
||||
<h2>Questions & Answers</h2>
|
||||
<h3>I'm not a miner or a merchant, what should I do?</h3>
|
||||
<p>
|
||||
Nothing. Your bitcoin software will switch to the correct chain automatically, no matter
|
||||
which version you are running.
|
||||
</p>
|
||||
<h3>Are my bitcoins safe?</h3>
|
||||
<p>
|
||||
Yes.
|
||||
</p>
|
||||
<h2>What will be done</h2>
|
||||
<p>
|
||||
The core developers have investigated what caused the old versions to reject the new
|
||||
blocks, and have released a 0.8.1 version that avoids creating blocks that are incompatible with
|
||||
older versions. <a href="https://en.bitcoin.it/wiki/BIP_50">A full post-mortem document has been published</a>.
|
||||
</p>
|
68
_alerts/2013-03-15-upgrade-deadline.html
Normal file
68
_alerts/2013-03-15-upgrade-deadline.html
Normal file
|
@ -0,0 +1,68 @@
|
|||
---
|
||||
title: "15 May 2013 Upgrade Deadline"
|
||||
lastmod: "10 May 2013 21:30 UTC"
|
||||
alias: "may15"
|
||||
active: false
|
||||
---
|
||||
<h2>What is happening</h2>
|
||||
<p>
|
||||
If you are using an old version of Bitcoin-Qt (or bitcoind, the server bitcoin software),
|
||||
you must either upgrade to version 0.8.0 or later before May 15, 2013,
|
||||
<a href="#backports">upgrade to an up-to-date "backport" release</a>,
|
||||
or <a href="#workaround">modify a file</a> and
|
||||
restart bitcoin to work around a bug with the old software.
|
||||
</p>
|
||||
<p>This bug does not affect any bitcoins you already have, but if you do nothing you will
|
||||
be out of sync with the rest of the Bitcoin network and will be unable to receive
|
||||
bitcoins (payments sent to you will look like they never get confirmed, or will be confirmed
|
||||
very slowly). You also risk being the victim of a "double-spend" attack, where somebody sends
|
||||
you bitcoins that the rest of the network would reject as invalid.
|
||||
</p>
|
||||
<p>
|
||||
We recommend that you
|
||||
<a href="https://sourceforge.net/projects/bitcoin/files/Bitcoin/bitcoin-0.8.1/">upgrade to version 0.8.1</a>
|
||||
before the 15th of May to avoid any issues. If you are a solo miner or mining pool operator,
|
||||
please see the the notes at the end of this page for how to upgrade safely.
|
||||
</p>
|
||||
<h2 id="backports">If you cannot upgrade to version 0.8.1</h2>
|
||||
<p>
|
||||
If you cannot upgrade to the latest version,
|
||||
<a href="https://bitcointalk.org/?topic=199699">backports to older branches are now in final testing</a>.
|
||||
These include not only compatibility for the 15 May changes, but also fixes for known vulnerabilities and bugs, which have already been included and tested in the latest release.
|
||||
</p>
|
||||
<h2 id="workaround">If you cannot upgrade to a backport</h2>
|
||||
<p>
|
||||
If you cannot upgrade to any of the above, you can still avoid the problem.
|
||||
Create a file called DB_CONFIG in the bitcoin data directory, containing this line:
|
||||
</p>
|
||||
<blockquote>
|
||||
<pre>
|
||||
set_lk_max_locks 537000
|
||||
</pre>
|
||||
</blockquote>
|
||||
<p>
|
||||
<a href="https://en.bitcoin.it/wiki/Data_directory">Look here</a> if you need help
|
||||
finding the bitcoin data directory.
|
||||
</p>
|
||||
<h2>Miners/mining pool operators</h2>
|
||||
<p>
|
||||
If you are creating new blocks (you are a solo miner or mining pool operator), then
|
||||
you should be aware that upgrading from 0.7 to 0.8 requires a lengthy
|
||||
re-indexing operation; you <b>must</b> wait for the reindex to complete before
|
||||
serving work to miners.
|
||||
</p>
|
||||
<p>
|
||||
And if you are creating blocks and cannot upgrade to version 0.8.1 or a
|
||||
backport for some
|
||||
reason, you should <b>not</b> set_lk_max_locks in a DB_CONFIG file until
|
||||
May 15th; if you increase locks before then you run the risk of creating
|
||||
or building on blocks incompatible with the rest of the network.
|
||||
</p>
|
||||
<h2>Why this is necessary</h2>
|
||||
<p>
|
||||
A bug caused a <a href="chainfork.html">temporary block chain fork on 11 March, 2013</a>.
|
||||
After investigating
|
||||
that bug, we determined that the bug can happen even if the entire network was
|
||||
still running old versions of Bitcoin-Qt/bitcoind. Therefore, the only option is to
|
||||
require everybody to either upgrade or workaround the bug.
|
||||
</p>
|
Loading…
Add table
Add a link
Reference in a new issue