CVE-2018-11687
Last modified
CVE-2018-11687 is a vulnerability of currently unknown severity. An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum ERC20 token, allows the owner to accomplish an unauthorized increase of digital assets by providing a large address[] array, as exploited in the wild in May 2018, aka the "ownerUnderflow" issue.. EPSS estimates a 1.28% chance of exploitation in the next 30 days.
Description
An integer overflow in the distributeBTR function of a smart contract implementation for Bitcoin Red (BTCR), an Ethereum ERC20 token, allows the owner to accomplish an unauthorized increase of digital assets by providing a large address[] array, as exploited in the wild in May 2018, aka the "ownerUnderflow" issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bitcoin Red Project | Bitcoin Red | All versions |
References
- https://www.anquanke.com/post/id/147913Third Party Advisory
- https://www.anquanke.com/post/id/147913Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-11687?
How severe is CVE-2018-11687?
How do I fix CVE-2018-11687?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11681Default and unremovable support credentials (user:nwk passwo…9.8
- CVE-2018-11682Default and unremovable support credentials allow attackers …9.8
- CVE-2018-11683Liblouis 3.5.0 has a stack-based Buffer Overflow in the func…
- CVE-2018-11684Liblouis 3.5.0 has a stack-based Buffer Overflow in the func…
- CVE-2018-11685Liblouis 3.5.0 has a stack-based Buffer Overflow in the func…
- CVE-2018-11686The Publish Service in FlexPaper (later renamed FlowPaper) 2…
- CVE-2018-11688Ignite Realtime Openfire before 3.9.2 is vulnerable to cross…
- CVE-2018-11689Web Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung W…6.1
- CVE-2018-1169This vulnerability allows remote attackers to execute arbitr…
- CVE-2018-11690The Balbooa Gridbox extension version 2.4.0 and previous ver…
- CVE-2018-11691Emerson DeltaV Smart Switch Command Center application, avai…
- CVE-2018-11692An issue was discovered on Canon LBP6650, LBP3370, LBP3460, …
Are you affected by CVE-2018-11687?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
