Skip to content

Heap Overflow in PyMiniRacer

Moderate
nizox published GHSA-vwcg-7xqw-qcxw Sep 18, 2020

Package

pip py-mini-racer (pip)

Affected versions

< 0.3.0

Patched versions

0.3.0

Description

A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.

More details on https://blog.sqreen.com/vulnerability-disclosure-finding-a-vulnerability-in-sqreens-php-agent-and-how-we-fixed-it/.

Severity

Moderate

CVE ID

CVE-2020-25489

Weaknesses

No CWEs