sherlock-audit / 2023-11-covalent-judging

3 stars 2 forks source link

krkba - Possible Integer Over Flow in `_secondsPerBlock` #57

Closed sherlock-admin2 closed 7 months ago

sherlock-admin2 commented 7 months ago

krkba

medium

Possible Integer Over Flow in _secondsPerBlock

krkba

Summary

Vulnerability Detail

There is possibility to Integer over flow attack, as example in _secondsPerBlock if it set more than maximum value of uint256 or less than minimum value of uint256.

Impact

It may produce unexpected results, leading to incorrect calculations.

Code Snippet

https://github.com/sherlock-audit/2023-11-covalent/blob/main/cqt-staking/contracts/BlockSpecimenProofChain.sol#L20

Tool used

Manual Review

Recommendation

Use safe math to prevent such things.

sherlock-admin2 commented 7 months ago

1 comment(s) were left on this issue during the judging contest.

takarez commented:

invalid

nevillehuang commented 7 months ago

Invalid, not reasonable to set such a high secondsperBlock.