Description
Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer from a potential buffer overrun. Importing a function from a JSON interface which returns `bytes` generates bytecode which does not clamp bytes length, potentially resulting in a buffer overrun. Users are advised to upgrade. There are no known workarounds for this issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0354 | Vyper is a pythonic Smart Contract Language for the ethereum virtual machine. Versions of vyper prior to 0.3.2 suffer from a potential buffer overrun. Importing a function from a JSON interface which returns `bytes` generates bytecode which does not clamp bytes length, potentially resulting in a buffer overrun. Users are advised to upgrade. There are no known workarounds for this issue. |
Github GHSA |
GHSA-4mrx-6fxm-8jpg | Buffer Overflow in vyper |
References
History
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:40:24.377Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24788
Updated: 2024-08-03T04:20:50.504Z
Status : Modified
Published: 2022-04-13T19:15:09.243
Modified: 2024-11-21T06:51:05.893
Link: CVE-2022-24788
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA