CVE-2024-32481
April 25, 2024
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when looping over a "range" of the form "range(start, start + N)", if "start" is negative, the execution will always revert. This issue is caused by an incorrect assertion inserted by the code generation of the range "stmt.parse_For_range()". The issue arises when "start" is signed, instead of using "sle", "le" is used and "start" is interpreted as an unsigned integer for the comparison. If it is a negative number, its 255th bit is set to "1" and is hence interpreted as a very large unsigned integer making the assertion always fail. Any contract having a "range(start, start + N)" where "start" is a signed integer with the possibility for "start" to be negative is affected. If a call goes through the loop while supplying a negative "start" the execution will revert. Version 0.4.0b1 fixes the issue.
Affected Packages
vyper (PYTHON):
Affected version(s) >=0.3.8 <0.4.0Fix Suggestion:
Update to version 0.4.0Related Resources (6)
Do you need more information?
Contact UsCVSS v4
Base Score:
6.9
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
LOW
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
5.3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE
Weakness Type (CWE)
Incorrect Conversion between Numeric Types
EPSS
Base Score:
1.17