Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the owner variable. This issue was fixed in version 0.3.8.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0269 | Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the owner variable. This issue was fixed in version 0.3.8.\n |
Github GHSA |
GHSA-mgv8-gggw-mrg6 | vyper vulnerable to storage allocator overflow |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 29 Jan 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-01-29T15:27:39.451Z
Reserved: 2023-04-18T16:13:15.879Z
Link: CVE-2023-30837
Updated: 2024-08-02T14:37:15.455Z
Status : Modified
Published: 2023-05-08T17:15:12.007
Modified: 2024-11-21T08:00:56.617
Link: CVE-2023-30837
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA