Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwpm-85r5-4m77

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.

An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.

EPSS

Процентиль: 65%
0.00484
Низкий

Дефекты

CWE-191

Связанные уязвимости

CVSS3: 7.5
nvd
почти 5 лет назад

An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.

EPSS

Процентиль: 65%
0.00484
Низкий

Дефекты

CWE-191