An integer underflow has been found in the latest version of ZCFees. The variables 'currPeriodIdx' and 'lastPeriodExecIdx' are both unsigned integers, and the result of the minus operation may be a negative integer which leads to an underflow. The attackers can modify the current timestamp of the transaction somehow and block the execution of the process function.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-02-10T15:40:21

Updated: 2021-02-10T15:40:21

Reserved: 2020-08-28T00:00:00


Link: CVE-2020-24837

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-02-10T16:15:13.630

Modified: 2021-02-17T13:38:05.907


Link: CVE-2020-24837

JSON object: View

cve-icon Redhat Information

No data.

CWE