Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS12aDN4LTUyNW0tanA0cs4AA_nK
heap-buffer-overflow in MicroPython
A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes.
Permalink: https://github.com/advisories/GHSA-vh3x-525m-jp4rJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12aDN4LTUyNW0tanA0cs4AA_nK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 26 days ago
Updated: 19 days ago
CVSS Score: 7.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Identifiers: GHSA-vh3x-525m-jp4r, CVE-2024-8948
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-8948
- https://github.com/micropython/micropython/issues/13041
- https://github.com/micropython/micropython/commit/908ab1ceca15ee6fd0ef82ca4cba770a3ec41894
- https://vuldb.com/?ctiid.277766
- https://vuldb.com/?id.277766
- https://vuldb.com/?submit.409317
- https://github.com/pypa/advisory-database/tree/main/vulns/micropython-copy/PYSEC-2024-87.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/micropython-io/PYSEC-2024-88.yaml
- https://github.com/pypa/advisory-database/tree/main/vulns/micropython-os/PYSEC-2024-89.yaml
- https://github.com/advisories/GHSA-vh3x-525m-jp4r
Blast Radius: 7.3
Affected Packages
pypi:micropython-os
Dependent packages: 0Dependent repositories: 10
Downloads: 400 last month
Affected Version Ranges: <= 0.8
No known fixed version
All affected versions: 0.2.3, 0.2.4, 0.3.1, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.7.1
pypi:micropython-io
Dependent packages: 0Dependent repositories: 2
Downloads: 84 last month
Affected Version Ranges: <= 0.1
No known fixed version
All affected versions: 0.0.1, 0.0.2, 0.0.3
pypi:micropython-copy
Dependent packages: 0Dependent repositories: 2
Downloads: 212 last month
Affected Version Ranges: <= 3.3.3.post3
No known fixed version
All affected versions: