PT-2018-12331 · Ethereum · Mkcb

Published

2018-07-16

·

Updated

2020-02-18

·

CVE-2018-14084

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MKCB (affected versions not specified)
Description An issue was discovered in the smart contract implementation for MKCB, an Ethereum token. The problem arises when the owner sets the value of sellPrice to a large number in the setPrices() function, which can cause an integer overflow in the sell() function due to the calculation amount * sellPrice.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14084

Affected Products

Mkcb