View at Official ubuntu advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2014-4501 medium priority: Ubuntu including 2 source packages (bfgminer, cgminer), 28 status rows across 14 suites (artful, bionic, cosmic, disco, lucid, precise, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): ignored 12, DNE 7, not-affected 7, released 2.
Multiple stack-based buffer overflows in sgminer before 4.2.2, cgminer before 4.3.5, and BFGMiner before 3.3.0 allow remote pool servers to have unspecified impact via a long URL in a client.reconnect stratum message to the (1) extract_sockaddr or (2) parse_reconnect functions in util.c.