PT-2022-23107 · Frontier · Frontier

Wei Tang

·

Published

2022-08-18

·

Updated

2022-08-25

·

CVE-2022-36008

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Frontier (affected versions not specified)
Description A security issue was discovered affecting the parsing of the RPC result of the exit reason in case of EVM reversion. This issue causes the exit reason to be incorrectly parsed and returned by RPC in release builds, and it causes an overflow panic in debug builds. The issue is relevant only if you have a bridge node that needs to distinguish different reversion exit reasons and you used RPC for this purpose.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2022-36008
GHSA-MJVM-MHGC-Q4GP

Affected Products

Frontier