CVE-2024-32481
MEDIUMDescription
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. Starting in version 0.3.8 and prior to version 0.4.0b1, when looping over a `range` of the form `range(start, start + N)`, if `start` is negative, the execution will always revert. This issue is caused by an incorrect assertion inserted by the code generation of the range `stmt.parse_For_range()`. The issue arises when `start` is signed, instead of using `sle`, `le` is used and `start` is interpreted as an unsigned integer for the comparison. If it is a negative number, its 255th bit is set to `1` and is hence interpreted as a very large unsigned integer making the assertion always fail. Any contract having a `range(start, start + N)` where `start` is a signed integer with the possibility for `start` to be negative is affected. If a call goes through the loop while supplying a negative `start` the execution will revert. Version 0.4.0b1 fixes the issue.
Is your site exposed to CVE-2024-32481?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| vyperlang | vyper |
| vyperlang | vyper |
References
Advisories & Patches
Exploits
Frequently Asked Questions
What is CVE-2024-32481? +
How severe is CVE-2024-32481? +
What products are affected by CVE-2024-32481? +
How do I check if I'm vulnerable to CVE-2024-32481? +
Related Vulnerabilities
GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through …
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
Microsoft ODBC Driver Remote Code Execution Vulnerability
Incorrect conversion between numeric types in Microsoft Office Word allows an unauthorized attacker to execute code locally.
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading …
dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This …