QID 980839
QID 980839: Python (pip) Security Update for py-evm (GHSA-vqgp-4jgj-5j64)
Py-EVM v0.2.0-alpha.33 allows attackers to make a vm.execute_bytecode call that triggers computation._stack.values with '"stack": [100, 100, 0]' where b'\x' was expected, resulting in an execution failure because of an invalid opcode. This is reportedly related to "smart contracts can be executed indefinitely without gas being paid."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vqgp-4jgj-5j64 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vqgp-4jgj-5j64 -
github.com/advisories/GHSA-vqgp-4jgj-5j64
CVEs related to QID 980839
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vqgp-4jgj-5j64 | py-evm |
|