CVEs assigned for lightning projects: please upgrade! [combined summary]



Individual post summaries: Click here to read the original discussion on the lightning-dev mailing list

Published on: 2019-09-10T15:25:31+00:00


Summary:

A security alert has been issued for lightning projects that have identified security issues, which could result in the loss of funds. The specific details regarding these issues will be disclosed in four weeks' time, on September 27, 2019. Users are strongly encouraged to upgrade their systems before this date to ensure their security measures are up to date.One of the affected releases is CVE-2019-12998 c-lightning. It is crucial for users to take immediate action and upgrade their systems as soon as possible to mitigate any potential loss of funds. This announcement serves as a reminder to all users to remain vigilant and take necessary precautions to protect their assets.To avoid risking any loss of funds, it is important for users to upgrade to fully patched versions such as lnd v0.7.1, c-lightning v0.7.1, and eclair v0.3.1. Additionally, there are still limits in place on the network to minimize widespread loss of funds. Users should keep this in mind when depositing funds onto the network at this early stage.If users encounter any difficulties while updating their implementation, they can seek assistance from developers. It is advised that users proactively take measures to ensure their security, including regularly upgrading their systems, keeping their software up to date, and staying informed about any security concerns or updates.By taking these actions, users can help prevent the loss of funds and maintain the integrity of their financial transactions. It is essential for users to prioritize their security and stay updated with the latest patches and upgrades to avoid potential vulnerabilities.


Updated on: 2023-07-31T21:53:21.904192+00:00