CVE-2023-39910, known as the "Milk Sad" issue, involves a weak cryptocurrency wallet entropy seeding mechanism in Libbitcoin Explorer versions 3.0.0 through 3.6.0. This vulnerability, categorized as CWE-338, stems from the use of an mt19937 Mersenne Twister PRNG, limiting internal entropy to 32 bits. With a CVSS score of 7.5 (HIGH), it allows remote attackers to recover private keys generated from "bx seed" output, leading to potential fund theft. This vulnerability has been actively exploited in the wild during June and July 2023, despite the vendor's claim of sufficient documentation advising against the vulnerable function. There is currently no public exploit code available, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.6.0CPE matchmatch criteria | cpe:2.3:a:libbitcoin:libbitcoin_explorer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.