CVE-2023-30837
Summary
| CVE | CVE-2023-30837 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-08 17:15:00 UTC |
| Updated | 2023-08-02 16:22:00 UTC |
| Description | Vyper is a pythonic smart contract language for the EVM. The storage allocator does not guard against allocation overflows in versions prior to 0.3.8. An attacker can overwrite the owner variable. This issue was fixed in version 0.3.8. |
Risk And Classification
Problem Types: CWE-789
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vyperlang | Vyper | All | All | All | All |
| Application | Vyper Project | Vyper | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Merge pull request from GHSA-mgv8-gggw-mrg6 · vyperlang/vyper@0bb7203 · GitHub | MISC | github.com | |
| Storage allocator overflow · Advisory · vyperlang/vyper · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.