CVE-2021-41121

Description

Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack. This issue has been resolved in version 0.3.0.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.423

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-41121,CVE-2021-41122,CVE-2024-32648 are fixed in Python-vyper 0.3.0Windows
Vulnerabilities CVE-2021-41121,CVE-2021-41122,CVE-2024-32648 are fixed in Python-vyper for linux 0.3.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234