The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker can then conduct a lockBalances() denial of service attack.
References
Link Resource
https://peckshield.com/2018/05/03/ownerAnyone/ Exploit Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-05-09T03:00:00

Updated: 2018-05-09T02:57:02

Reserved: 2018-05-03T00:00:00


Link: CVE-2018-10705

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-05-09T03:29:00.230

Modified: 2019-10-03T00:03:26.223


Link: CVE-2018-10705

JSON object: View

cve-icon Redhat Information

No data.