VDB
CVE-2023-7158
CVE-2023-7158
PUBLISHED
CVSS 7.300000190734863 HIGH
A vulnerability was found in MicroPython up to 1.21.0. It has been classified as critical. Affected is the function slice_indices of the file objslice.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.22.0 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-249180.
EPSS 1.23% · 67.9th percentile
Risk Scores
CVSS 3.1
7.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS Score
1.23%
67.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | MicroPython | 1.21.0, 1.13.0, 1.14.0 |
| micropython | micropython | 0 |
Timeline
- Jan 20, 1970 Fix PR Merged
- Jan 20, 1970 Fix PR Merged
- Dec 29, 2023 EPSS Score
- Dec 29, 2023 CVE Published
- Jan 27, 2024 EPSS Score
- Feb 26, 2024 EPSS Score
- Apr 24, 2024 EPSS Score
- May 23, 2024 EPSS Score
- Jun 22, 2024 EPSS Score
- Jul 21, 2024 EPSS Score
- Sep 17, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
References
- https://github.com/micropython/micropython/issues/13007 discussion
- https://github.com/micropython/micropython/pull/13039 fix
- https://github.com/micropython/micropython/pull/13039/commits/f397a3ec318f3ad05aa287764ae7cef32202380f fix
- https://github.com/micropython/micropython/releases/tag/v1.22.0 fix
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEK46QAJOXXDZOWOIE2YACUOCZFWOBCK/ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D3WWY5JY4RTJE25APB4REGDUDPATG6H7/ url
- https://vuldb.com/?id.249180 vdb
- https://vuldb.com/?ctiid.249180 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4E2HYWCZB5R4SHY4SZZZSFDMD64N4SOZ/ url
- https://nvd.nist.gov/vuln/detail/CVE-2023-7158 advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4E2HYWCZB5R4SHY4SZZZSFDMD64N4SOZ url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/D3WWY5JY4RTJE25APB4REGDUDPATG6H7 url
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TEK46QAJOXXDZOWOIE2YACUOCZFWOBCK url