code-423n4 / 2023-07-pooltogether-findings

12 stars 7 forks source link

prb-math not audited #195

Closed code423n4 closed 1 year ago

code423n4 commented 1 year ago

Lines of code

https://github.com/GenerationSoftware/pt-v5-claimer/blob/57a381aef690a27c9198f4340747155a71cae753/src/libraries/LinearVRGDALib.sol#L4-L5

Vulnerability details

Impact

The library prb-math documents that it is not audited by a security researcher. This means its more risky to rely on this library.

Proof of Concept

// https://github.com/hifi-finance/prb-math#security The contracts have not been audited by a security researcher.

Tools Used

Manual

Recommended Mitigation Steps

Consider (crowdsourcing) an audit for prb-math

Assessed type

Library

c4-judge commented 1 year ago

Picodes marked the issue as duplicate of #423

c4-judge commented 1 year ago

Picodes marked the issue as partial-25

c4-judge commented 1 year ago

Picodes marked the issue as not a duplicate

Picodes commented 1 year ago

Downgrading to QA as this report doesn't showcase any bug

c4-judge commented 1 year ago

Picodes changed the severity to QA (Quality Assurance)

c4-judge commented 1 year ago

Picodes marked the issue as grade-c