Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-8948

Опубликовано: 17 сент. 2024
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5
CVSS3: 7.3

Описание

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes.

РелизСтатусПримечание
devel

not-affected

1.24.1+ds-1
esm-apps/focal

ignored

changes too intrusive
esm-apps/jammy

ignored

changes too intrusive
esm-apps/noble

ignored

changes too intrusive
focal

ignored

end of standard support, was needs-triage
jammy

needs-triage

noble

needs-triage

oracular

ignored

end of life, was ignored [changes too intrusive]
plucky

not-affected

1.24.1+ds-1
questing

not-affected

1.24.1+ds-1

Показывать по

7.5 High

CVSS2

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
больше 1 года назад

A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes.

CVSS3: 7.3
debian
больше 1 года назад

A vulnerability was found in MicroPython 1.23.0. It has been rated as ...

CVSS3: 7.3
github
больше 1 года назад

heap-buffer-overflow in MicroPython

7.5 High

CVSS2

7.3 High

CVSS3