missing clamps for decimal args in external functions
Description
Published by the National Vulnerability Database
Oct 5, 2021
Reviewed
Oct 6, 2021
Published to the GitHub Advisory Database
Oct 6, 2021
Last updated
Nov 18, 2024
Impact
The following code does not properly validate that its input is in bounds.
Patches
0.3.0 / #2447
Workarounds
Don't use decimal args
References