Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12aDN4LTUyNW0tanA0cs4AA_nK

heap-buffer-overflow in MicroPython

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes.

Permalink: https://github.com/advisories/GHSA-vh3x-525m-jp4r
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12aDN4LTUyNW0tanA0cs4AA_nK
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 1 month ago
Updated: 24 days ago


CVSS Score: 7.3
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Identifiers: GHSA-vh3x-525m-jp4r, CVE-2024-8948
References: Repository: https://github.com/micropython/micropython
Blast Radius: 7.3

Affected Packages

pypi:micropython-os
Dependent packages: 0
Dependent repositories: 10
Downloads: 400 last month
Affected Version Ranges: <= 0.8
No known fixed version
All affected versions: 0.2.3, 0.2.4, 0.3.1, 0.4.1, 0.4.2, 0.4.3, 0.4.4, 0.7.1
pypi:micropython-io
Dependent packages: 0
Dependent repositories: 2
Downloads: 84 last month
Affected Version Ranges: <= 0.1
No known fixed version
All affected versions: 0.0.1, 0.0.2, 0.0.3
pypi:micropython-copy
Dependent packages: 0
Dependent repositories: 2
Downloads: 212 last month
Affected Version Ranges: <= 3.3.3.post3
No known fixed version
All affected versions: