pallet-evm-precompile-modexp
Activity
- Latest release
- 5y ago
- Total releases
- 1
- Cadence
- —
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Apr 07, 2021
| Version | Released | |
|---|---|---|
1.0.0
unknown
2 CVEs
CVE-2023-28431
GHSA-fcmm-54jp-7vf6
Mar 21, 2023
Frontier's modexp precompile is slow for even modulus
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
ImpactFrontier's PatchesNo fixes for The short-term fix for Frontier is deployed at PR 1017. The recommendations are as follows:
WorkaroundsNone. ReferencesA similar issue was presented in Geth's implementation and the fix can be found here. References
Updated Oct 24, 2024 · Source: OSV.dev
CVE-2022-21685
GHSA-cjg2-2fjg-fph4
Jan 14, 2022
Integer underflow in Frontier
Medium
ImpactA bug in Frontier's MODEXP precompile implementation can cause an integer underflow in certain conditions. This will cause a node crash for debug builds. For release builds (and production WebAssembly binaries), the impact is limited as it can only cause a normal EVM out-of-gas. It is recommended that you apply the patch as soon as possible. If you do not use MODEXP precompile in your runtime, then you are not impacted. PatchesPatches are applied in PR #549. WorkaroundsNone. ReferencesPatch PR: #549 CreditsThanks to SR-Labs for discovering the security vulnerability, and thanks to PureStake team for the patches. For more informationIf you have any questions or comments about this advisory:
References
Updated Oct 24, 2024 · Source: OSV.dev |
1.0.0
unknown
Dependencies (6)
|