CVE-2023-42460
CVSS V2 None
CVSS V3 None
Description
Vyper is a Pythonic Smart Contract Language for the EVM. The `_abi_decode()` function does not validate input when it is nested in an expression. Uses of `_abi_decode()` can be constructed which allow for bounds checking to be bypassed resulting in incorrect results. This issue has not yet been fixed, but a fix is expected in release `0.3.10`. Users are advised to reference pull request #3626.
Overview
- CVE ID
- CVE-2023-42460
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-09-26T18:47:09.721Z
- Last Modified Date
- 2023-09-26T18:47:09.721Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/vyperlang/vyper/security/advisories/GHSA-cx2q-hfxr-rj97 | x_refsource_CONFIRM |
https://github.com/vyperlang/vyper/pull/3626 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-42460 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42460 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 13:48:56 | Added to TrackCVE |