VDB
CVE-2023-7158
CVE-2023-7158
PUBLISHED
CVSS 7.300000190734863 HIGH
A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.22.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249180.
EPSS 1.23% · 66.0th percentile
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
1.23%
66.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | MicroPython | 1.21.0, 1.13.0, 1.14.0 |
| micropython | micropython | 0 |
Timeline
- Jan 20, 1970 Fix PR Merged
- Jan 20, 1970 Fix PR Merged
- Dec 29, 2023 EPSS Score
- Dec 29, 2023 CVE Published
- Jan 27, 2024 EPSS Score
- Feb 24, 2024 EPSS Score
- Apr 22, 2024 EPSS Score
- May 21, 2024 EPSS Score
- Jun 18, 2024 EPSS Score
- Jul 17, 2024 EPSS Score
- Aug 15, 2024 EPSS Score
- Sep 13, 2024 EPSS Score
References
- https://github.com/micropython/micropython/issues/13007 exploit
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEK46QAJOXXDZOWOIE2YACUOCZFWOBCK/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D3WWY5JY4RTJE25APB4REGDUDPATG6H7/ url
- https://vuldb.com/?id.249180 vdb
- https://vuldb.com/?ctiid.249180 url
- https://github.com/micropython/micropython/pull/13039 issue
- https://github.com/micropython/micropython/pull/13039/commits/f397a3ec318f3ad05aa287764ae7cef32202380f issue
- https://github.com/micropython/micropython/releases/tag/v1.22.0 patch
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4E2HYWCZB5R4SHY4SZZZSFDMD64N4SOZ/ url
- https://nvd.nist.gov/vuln/detail/CVE-2023-7158 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4E2HYWCZB5R4SHY4SZZZSFDMD64N4SOZ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D3WWY5JY4RTJE25APB4REGDUDPATG6H7 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEK46QAJOXXDZOWOIE2YACUOCZFWOBCK url