X-CASH-official / xcash-core

📦 First Cryptonote coin with public & private transactions, custom DPOS consensus
https://xcash.foundation
Other
66 stars 20 forks source link

Seg fault when calling delegate_register without all parameters #8

Closed picatextra closed 4 years ago

zachhildreth commented 4 years ago

Hi @picatextra Yes I can confirm that if not all parameters are given it will segfault instead of giving an error message

This behavior has been changed in this commit

We are awarding the bug bounty for this bug to you!

CVSS Score

We have determined that the CVSS score for this bug is a 0

So according to the Bug Bounty official documentation this bug qualifies for a award between $5.00 and 25.00 USD

We have calculated the final amount in USD based on the following criteria

Question Answer
How long I have spent on the bug N/A
How often does the bug occur only if the user does not provide correct parameters
Was there any modification to the code to create the bug NO
Did the user provide a full code fix NO
Did the bug have to do with multi-threading NO
Could the tester use a debugger, static analysis or both both
Are we currently in Alpha, Beta or Live implementation of DPOPS ALPHA

Based on the above the team has decided that the final awarded amount will be $5.00 USD

Please post a X-CASH Wallet address in the comments, and we will send the payment in a public transaction, post the transaction hash and then close the issue.

Thank you for helping out the DPOPS by finding this bug.

picatextra commented 4 years ago

XCA1ka4bXH1bnvdT8vti1S12PfyH8fJ5XDUXyNRusyMRTBfFCawywJyCV5vvG38h71GAv77WotbmwbmbJen5bQpC7GeVx8gSws

zachhildreth commented 4 years ago

Date: 2019-10-21 Amount (USD): $5 Amount (XCASH): 155544.92 XCASH Spot Price: 0.0000321450563020242 USD/XCASH XCASH Address: XCA1ka4bXH1bnvdT8vti1S12PfyH8fJ5XDUXyNRusyMRTBfFCawywJyCV5vvG38h71GAv77WotbmwbmbJen5bQpC7GeVx8gSws Tx Hash: ddffadf7d44ef1fc69bd3af886c899194fa4826bf770052174ee7ecf8317b458 Link: https://explorer.x-cash.org/Transaction?data=ddffadf7d44ef1fc69bd3af886c899194fa4826bf770052174ee7ecf8317b458 "Bounty Paid ✅