yocto ▾
›
master ▾
›
vulnerability
›
CVE-2018-13684
Component Overview
Vulnerability Overview
Name
CVE-2018-13684
Source
NVD (
link
)
Debian (
link
)
Description
The mintToken function of a smart contract implementation for ZIP, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
CWEs
CWE-190
Published Date
Jul 9, 2018
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md
Exploit
https://github.com/BlockChainsSecurity/EtherTokens/tree/master/ZIP
Third Party Advisory
https://github.com/BlockChainsSecurity/EtherTokens/blob/master/GEMCHAIN/mint%20integer%20overflow.md
Exploit
https://github.com/BlockChainsSecurity/EtherTokens/tree/master/ZIP
Third Party Advisory
Analysis
#
Affected Component
Analysis
zip
False Positive
Vulnerability Ratings
#
7.5
other
5
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
zip
buildroot
2025.02.x
3.0
Not Affected
zip
buildroot
master
3.0
Not Affected
zip
yocto
kirkstone
3.0
Not Affected
zip
yocto
scarthgap
3.0
False Positive