CVE-2020-11014
Summary
| CVE | CVE-2020-11014 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-28 20:15:00 UTC |
| Updated | 2020-05-06 18:22:00 UTC |
| Description | Electron-Cash-SLP before version 3.6.2 has a vulnerability. All token creators that use the "Mint Tool" feature of the Electron Cash SLP Edition are at risk of sending the minting authority baton to the wrong SLP address. Sending the mint baton to the wrong address will give another party the ability to issue new tokens or permanently destroy future minting capability. This is fixed version 3.6.2. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Simpleledger | Electron-cash-slp | All | All | All | All |
| Application | Simpleledger | Electron-cash-slp | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| BIP LI01 output reordering may cause malformed SLP MINT transactions · Advisory · simpleledger/Electron-Cash-SLP · GitHub | CONFIRM | github.com | Third Party Advisory |
| patch for critical vulnerability in mint tool · simpleledger/Electron-Cash-SLP@ea3912c · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Mint baton sent to token receiver address · Issue #126 · simpleledger/Electron-Cash-SLP · GitHub | MISC | github.com | Third Party Advisory |
| rfc/bip-li01.mediawiki at master · kristovatlas/rfc · GitHub | MISC | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.