Launch Week Day 1: Announcing Security Design Review
HIGH 7.1 PyPI

Buffer Overflow in vyper

GHSA-4mrx-6fxm-8jpg · CVE-2022-24788 · PYSEC-2022-197

Published · Modified

Description

Impact

Importing a function from a JSON interface which returns bytes generates bytecode which does not clamp bytes length, potentially resulting in a buffer overrun.

Patches

0.3.2 (as of https://github.com/vyperlang/vyper/commit/049dbdc647b2ce838fae7c188e6bb09cf16e470b)

Workarounds

Use .vy interfaces.

Ready to move

Start Securing

Free, no credit card | First findings in minutes