logo

CVE-2020-25489 py-mini-racer

Package

Manager: pip
Name: py-mini-racer
Vulnerable Version: >=0 <0.3.0

Severity

Level: High

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

EPSS: 0.01073 pctl0.76936

Details

Heap Overflow in PyMiniRacer A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption. More details on https://blog.sqreen.com/vulnerability-disclosure-finding-a-vulnerability-in-sqreens-php-agent-and-how-we-fixed-it/.

Metadata

Created: 2020-09-18T18:03:59Z
Modified: 2024-10-21T20:25:05Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-vwcg-7xqw-qcxw/GHSA-vwcg-7xqw-qcxw.json
CWE IDs: ["CWE-119"]
Alternative ID: GHSA-vwcg-7xqw-qcxw
Finding: F316
Auto approve: 1