Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler for a .desktop file or a web browser. NOTE: the discoverer states "I believe that this vulnerability cannot actually be exploited."
- https://github.com/bitcoin/bitcoin/pull/16578
- https://github.com/ARPSyndicate/cvemon
- https://github.com/VPRLab/BlkVulnReport
- https://github.com/uvhw/conchimgiangnang