Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ensure that field lengths are limited #1370

Closed
faddat opened this issue Oct 19, 2023 · 1 comment · Fixed by #1460
Closed

Ensure that field lengths are limited #1370

faddat opened this issue Oct 19, 2023 · 1 comment · Fixed by #1460
Assignees

Comments

@faddat
Copy link
Contributor

faddat commented Oct 19, 2023

Over a year ago, a researcher named Twitter.com/Ctrl_felix discovered an issue in IBC which is now named banana King after the receive address that he chose in a multi-megabyte IBC transfer. Felix reported to hacker one but did not hear back, and then twitter.com/getcoldy contacted me for assistance with that.

Over a year ago, when contacted for assistance by Colby, I responded and contacted the informal systems and IBC teams. Somehow, the SDK and comet became involved as well. Unfortunately, nothing was done. We need to check ICS to make sure that all fields have bounds.

@github-project-automation github-project-automation bot moved this to 🩹 F1: Triage in Cosmos Hub Oct 19, 2023
@mpoke mpoke moved this from 🩹 F1: Triage to 📥 F2: Todo in Cosmos Hub Nov 9, 2023
@mpoke mpoke moved this from 📥 F2: Todo to 🏗 F3: InProgress in Cosmos Hub Nov 9, 2023
@mpoke mpoke self-assigned this Nov 9, 2023
@mpoke mpoke moved this from 🏗 F3: InProgress to 🤔 F1: Investigate in Cosmos Hub Nov 9, 2023
@mpoke mpoke moved this from 🤔 F1: Investigate to 🏗 F3: InProgress in Cosmos Hub Nov 28, 2023
@mpoke mpoke moved this from 🏗 F3: InProgress to 👀 F3: InReview in Cosmos Hub Nov 30, 2023
@github-project-automation github-project-automation bot moved this from 👀 F3: InReview to 👍 F4: Assessment in Cosmos Hub Dec 1, 2023
@mpoke
Copy link
Contributor

mpoke commented Dec 1, 2023

Thanks @faddat for opening this issue. Check the fix in #1460.

@mpoke mpoke moved this from 👍 F4: Assessment to ✅ Done in Cosmos Hub Dec 1, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
Status: ✅ Done
Development

Successfully merging a pull request may close this issue.

2 participants