VDB
Sign up
—

RUSTSEC-2024-0338

Arithmetic overflows in cosmwasm-std

Details

Some mathematical operations in `cosmwasm-std` use wrapping math instead of panicking on overflow for very big numbers. This can lead to wrong calculations in contracts that use these operations.

Affected functions:

- `Uint{256,512}::pow` / `Int{256,512}::pow` - `Int{256,512}::neg`

Affected if `overflow-checks = true` is not set:

- `Uint{64,128}::pow` / `Int{64,128}::pow` - `Int{64,128}::neg`

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/cosmwasm-std
Introduced in: 1.3.0Fixed in: 1.4.4

Upgrade cosmwasm-std to 1.4.4 or newer (ecosystem crates.io).

References