LEGACY_STATUS_PROVEN, LEGACY_STATUS_PROCESSED, and LEGACY_STATUS_NONE were the newly introduced constants in commit 46d145, which was not part of the audit. The acceptableRoot public function only handled 2 constants. This exploit could have been prevented with more testing. https://t.co/Xk8DQK1Y2Q

LEGACY_STATUS_PROVEN、LEGACY_STATUS_PROCESSED 和 LEGACY_STATUS_NONE 是提交 46d145 中新引入的常量,这不是审计的一部分。可接受的根公共函数只处理 2 个常量。通过更多的测试可以防止这种利用。 https://t.co/Xk8DQK1Y2Q

发表时间:1年前 作者:Quantstamp @Quantstamp