The approveAndCallcode function of a smart contract implementation for Block 18 (18T), an tradable Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into their account) because the callcode (i.e., _spender.call(_extraData)) is not verified, aka the "evilReflex" issue. NOTE: a PeckShield disclosure states "some researchers have independently discussed the mechanism of such vulnerability."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2018-06-25T10:00:00

Updated: 2024-08-05T08:45:01.179Z

Reserved: 2018-06-23T00:00:00

Link: CVE-2018-12703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-06-25T10:29:00.267

Modified: 2018-08-30T13:16:41.657

Link: CVE-2018-12703

cve-icon Redhat

No data.