CVE-2018-13877

The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.
Configurations

Configuration 1 (hide)

cpe:2.3:a:megacryptopolis:megacryptopolis:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:48

Type Values Removed Values Added
References () https://medium.com/coinmonks/denial-of-service-dos-attack-on-megacryptopolis-an-ethereum-game-cve-2018-13877-cdd7f7ef8b08 - Broken Link () https://medium.com/coinmonks/denial-of-service-dos-attack-on-megacryptopolis-an-ethereum-game-cve-2018-13877-cdd7f7ef8b08 - Broken Link

Information

Published : 2018-08-06 20:29

Updated : 2024-11-21 03:48


NVD link : CVE-2018-13877

Mitre link : CVE-2018-13877

CVE.ORG link : CVE-2018-13877


JSON object : View

Products Affected

megacryptopolis

  • megacryptopolis
CWE
CWE-20

Improper Input Validation