Vulnerability Description
An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacker to create an arbitrary amount of tokens for any user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cryptobots | Battletoken | - |
Related Weaknesses (CWE)
References
- https://etherscan.io/address/0x4daa9dc438a77bd59e8a43c6d46cbfe84cd04255#codeThird Party Advisory
- https://github.com/GreenFoxy/Smart-contract-Vulnerabilities/blob/master/BattleToExploitThird Party Advisory
- https://etherscan.io/address/0x4daa9dc438a77bd59e8a43c6d46cbfe84cd04255#codeThird Party Advisory
- https://github.com/GreenFoxy/Smart-contract-Vulnerabilities/blob/master/BattleToExploitThird Party Advisory
FAQ
What is CVE-2018-17882?
CVE-2018-17882 is a vulnerability with a CVSS score of 7.5 (HIGH). An Integer overflow vulnerability exists in the batchTransfer function of a smart contract implementation for CryptoBotsBattle (CBTB), an Ethereum token. This vulnerability could be used by an attacke...
How severe is CVE-2018-17882?
CVE-2018-17882 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17882?
Check the references section above for vendor advisories and patch information. Affected products include: Cryptobots Battletoken.