-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use call instead of transfer #33
Labels
bug
Something isn't working
duplicate
This issue or pull request already exists
primary issue
Highest quality submission among a set of duplicates
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
responded
The Holograph team has reviewed and responded
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
Comments
code423n4
added
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
labels
Oct 19, 2022
Duplicate of #452 |
gzeoneth
added
the
primary issue
Highest quality submission among a set of duplicates
label
Oct 28, 2022
This was referenced Oct 28, 2022
Closed
Closed
gzeoneth
added
the
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
label
Oct 31, 2022
|
gzeoneth
added
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
and removed
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
labels
Nov 19, 2022
Consider with #36 |
15 tasks
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
bug
Something isn't working
duplicate
This issue or pull request already exists
primary issue
Highest quality submission among a set of duplicates
QA (Quality Assurance)
Assets are not at risk. State handling, function incorrect as to spec, issues with clarity, syntax
responded
The Holograph team has reviewed and responded
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
Lines of code
https://github.com/holographxyz/holograph-protocol/blob/c4_audit/contracts/enforcer/PA1D.sol#L396
Vulnerability details
Impact
The transfer function is not recommended for sending ETH due to its 2300 gas unit limit. Instead call can be used to circumvent the gas limit
Proof of Concept
Recommended Mitigation Steps
Use call instead of transfer
The text was updated successfully, but these errors were encountered: