CVE-2018-11687 describes an integer overflow vulnerability in the distributeBTR function of the Bitcoin Red (BTCR) ERC20 token smart contract. This flaw allows the contract owner to illicitly inflate digital assets by supplying an excessively large array of addresses. Rated with a CVSS score of 7.5 (HIGH), the vulnerability is easily exploitable over the network with low complexity, leading to high integrity impact. While exploited in the wild in May 2018, there are currently no public exploit tools, and it has received minimal community or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:bitcoin_red_project:bitcoin_red:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.