mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-05 06:38:06 +02:00
23 lines
1.0 KiB
Markdown
23 lines
1.0 KiB
Markdown
### [CVE-2018-11687](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11687)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum ERC20 token, allows the owner to accomplish an unauthorized increase of digital assets by providing a large address[] array, as exploited in the wild in May 2018, aka the "ownerUnderflow" issue.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
No PoCs from references.
|
|
|
|
#### Github
|
|
- https://github.com/DSKPutra/Buggy-ERC20-Tokens
|
|
- https://github.com/SruthiPriya11/audit
|
|
- https://github.com/devmania1223/awesome-buggy-erc20-tokens
|
|
- https://github.com/mitnickdev/buggy-erc20-standard-token
|
|
- https://github.com/rjhorniii/DICOM-YARA-rules
|
|
- https://github.com/sec-bit/awesome-buggy-erc20-tokens
|
|
|