The buyer of an option can overpay #234
Labels
2 (Med Risk)
Assets not at direct risk, but function/availability of the protocol could be impacted or leak value
bug
Something isn't working
duplicate
This issue or pull request already exists
sponsor confirmed
Sponsor agrees this is a problem and intends to fix it (OK to use w/ "disagree with severity")
Lines of code
https://github.com/code-423n4/2022-05-cally/blob/1849f9ee12434038aa80753266ce6a2f2b082c59/contracts/src/Cally.sol#L224
Vulnerability details
Impact
Buyers can lose funds if they overpay for an option
Proof of Concept
The code verifies msg.value >= price. The verification should be msg.value == price to ensure buyers don't overpay for their option.
https://github.com/code-423n4/2022-05-cally/blob/1849f9ee12434038aa80753266ce6a2f2b082c59/contracts/src/Cally.sol#L224
Recommended Mitigation Steps
Change >= for ==
The text was updated successfully, but these errors were encountered: