Trail of Bits

RSKj

Type

Security review

Client

RSK

Date

2017-11

Domain

Blockchain

Effort

6 wks

Section

Bitcoin & Derivatives

Trail of Bits's security review of RSK (Nov 2017) identified 10 issues: 2 high, 3 medium, 2 informational, and 3 undetermined.

Findings · 10

  1. 1 Resource Leaks in Trie Undetermined
  2. 2 Headers Not Properly Deleted in the BlockStore Undetermined
  3. 3 Infinite Loop in EthereumJ Key Verification Informational
  4. 4 Integrate Infer into the RSKj Build Process Informational
  5. 5 Erroneous Gas Computation in CALL Breaks Sending Ether to a Contract High
  6. 6 Wrong msg.value Parameter in CREATE Leads to a Broken Contract High
  7. 7 Duplicated Logs May Lead to Misinterpreted Events Medium
  8. 8 Incorrect Gas Computation in Modexp Medium
  9. 9 Missing Implementation of EIPs May Lead to Denial of Service Medium
  10. 10 Incorrect Encoding Implementation Leads to Wrong RLP Encoding Undetermined

Findings extracted from the published report PDF. See the full report below for details and remediation.

Related