CVE-2024-24564
CVSS 3.1 Score 3.7 of 10 (low)
Attack Complexity high
Confidentiality low
Integrity none
Availability none
Scope unchanged
Privileges Required none
Details
Published Feb 26, 2024
CWE ID 125
Summary
CVE-2024-24564 is a vulnerability affecting Vyper, a pythonic Smart Contract Language for the ethereum virtual machine. The issue arises when the `extract32(b, start)` function is used, with `start` having side effects that update the byte array `b`. This can result in the reading and returning of corrupt or dirty memory instead of the intended 32 bytes. This vulnerability poses a risk for applications using Vyper version 0.3.10 and earlier.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share