Metrics
Affected Vendors & Products
Mon, 23 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-787 | |
CPEs | cpe:2.3:a:micropython:micropython:1.23.0:*:*:*:*:*:*:* |
Wed, 18 Sep 2024 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Micropython
Micropython micropython |
|
CPEs | cpe:2.3:a:micropython:micropython:*:*:*:*:*:*:*:* | |
Vendors & Products |
Micropython
Micropython micropython |
|
Metrics |
ssvc
|
Tue, 17 Sep 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes. | |
Title | MicroPython objint.c mpz_as_bytes heap-based overflow | |
Weaknesses | CWE-122 | |
References |
| |
Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2024-09-17T18:50:17.599Z
Updated: 2024-09-17T20:07:19.189Z
Reserved: 2024-09-17T12:47:17.459Z
Link: CVE-2024-8948
Updated: 2024-09-17T20:07:14.945Z
Status : Analyzed
Published: 2024-09-17T19:15:29.747
Modified: 2024-09-23T18:10:28.273
Link: CVE-2024-8948
No data.