{"id":"GHSA-xfrc-7mj2-5xh9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xfrc-7mj2-5xh9","summary":"Undefined Behavior in zencashjs","details":"Versions of `zencashjs` prior to 1.2.0 may cause loss of funds when used with cryptocurrency wallets. The package relies on a string comparison of the first two characters of a Horizen address to determine the destination address type of a transaction (P2PKH or P2SH). Due to the base58 address prefixes chosen in Horizen there exists the possibility of a clash of address prefixes for testnet P2PKH and mainnet P2SH addresses, testnet P2PKH addresses start with “zt” while a subset of mainnet P2SH addresses can also start with “zt”. The package interprets transactions sent to a “zt” P2SH address on mainnet as P2PKH transactions erroneously. Any funds sent to a mainnet P2SH multisignature address starting with “zt” will be sent to the wrong address and be lost.\n\n\n## Recommendation\n\nUpgrade to version 1.2.0 or later.","published":"2020-09-03T17:14:51Z","modified":"2020-08-31T18:44:53Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"zencashjs","fixedVersion":"1.2.0"}],"fix":{"url":"https://github.com/ZencashOfficial/zencashjs/commit/db01bd94b9f8a956d7835e934500eaa643f8bd13#diff-42d8d2088a96641b563b25ad908b0c0fR146","label":"ZencashOfficial/zencashjs@db01bd9"},"references":[{"type":"WEB","url":"https://github.com/ZencashOfficial/zencashjs/commit/db01bd94b9f8a956d7835e934500eaa643f8bd13#diff-42d8d2088a96641b563b25ad908b0c0fR146"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1035"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2020-08-31T18:44:53Z"}}