CVE-2021-41122
Summary
| CVE | CVE-2021-41122 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-05 23:15:00 UTC |
| Updated | 2023-08-02 16:22:00 UTC |
| Description | Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions external functions did not properly validate the bounds of decimal arguments. The can lead to logic errors. This issue has been resolved in version 0.3.0. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| rewrite internal calling convention by charles-cooper · Pull Request #2447 · vyperlang/vyper · GitHub |
MISC |
github.com |
|
| missing clamps for decimal args in external functions · Advisory · vyperlang/vyper · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980492 Python (pip) Security Update for vyper (GHSA-c7pr-343r-5c46)