CVE-2020-24838
Summary
| CVE | CVE-2020-24838 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-02-10 16:15:00 UTC |
| Updated | 2021-02-17 14:53:00 UTC |
| Description | An integer overflow has been found in the the latest version of Issuer. The total issuedCount can be zero if the parameter is overly large. An attacker can obtain the private key of the owner issued with a certain 'amount', and the issuedCount can be zero if there is an overflow. |
Risk And Classification
Problem Types: CWE-190
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Issuer Project | Issuer | - | All | All | All |
| Application | Issuer Project | Issuer | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Issuer | 0xecaad8df0dee0b9ed45ffd1191b024701f21506c | MISC | etherscan.io | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.