CVE-2024-8948
heap-buffer-overflow in MicroPython
7.3
HIGH
CVSS 3.1
EPSS 0.98%
描述
A vulnerability was found in MicroPython 1.23.0. It has been rated as critical. Affected by this issue is the function mpz_as_bytes of the file py/objint.c. The manipulation leads to heap-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894. It is recommended to apply a patch to fix this issue. In micropython objint component, converting zero from int to bytes leads to heap buffer-overflow-write at mpz_as_bytes.
如何修補 CVE-2024-8948
要修補 CVE-2024-8948,請將受影響套件升級到下列已修補版本。
- —升級至 1.24.0+ds-1 或更新版本
- —未列出修補版本
- —升級至 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894 或更新版本
- —未列出修補版本
- —升級至 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894 或更新版本
- —未列出修補版本
- —升級至 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894 或更新版本
CVE-2024-8948 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(7)
- from 0, < 1.24.0+ds-1
- from 0, <= 3.3.3.post3
- from 0, < 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894 | from 0
- from 0, <= 0.1
- from 0, < 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894 | from 0
- from 0, <= 0.8
- from 0, < 908ab1ceca15ee6fd0ef82ca4cba770a3ec41894 | from 0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 4.0 | — | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
| osv | CVSS 3.1 | HIGH7.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |