icon

We found results for “

CVE-2023-32058

Good to know:

icon
icon

Date: May 11, 2023

Vyper is a Pythonic smart contract language for the Ethereum virtual machine. Prior to version 0.3.8, due to missing overflow check for loop variables, by assigning the iterator of a loop to a variable, it is possible to overflow the type of the latter. The issue seems to happen only in loops of type "for i in range(a, a + N)" as in loops of type "for i in range(start, stop)" and "for i in range(stop)", the compiler is able to raise a "TypeMismatch" when trying to overflow the variable. The problem has been patched in version 0.3.8.

Language: Python

Severity Score

Severity Score

Weakness Type (CWE)

Integer Overflow or Wraparound

CWE-190

Top Fix

icon

Upgrade Version

Upgrade to version vyper - 0.3.8

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): NONE
Availability (A): HIGH

Do you need more information?

Contact Us