PT-2022-23107 · Frontier · Frontier
Wei Tang
·
Published
2022-08-18
·
Updated
2022-08-25
·
CVE-2022-36008
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Frontier (affected versions not specified)
Description
A security issue was discovered affecting the parsing of the RPC result of the exit reason in case of EVM reversion. This issue causes the exit reason to be incorrectly parsed and returned by RPC in release builds, and it causes an overflow panic in debug builds. The issue is relevant only if you have a bridge node that needs to distinguish different reversion exit reasons and you used RPC for this purpose.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frontier