VDB
Sign up

PYSEC-2019-242

Withdrawn 2024-11-22. This finding no longer applies and is kept for reference. It is not used when checking packages.

Quick fix

PYSEC-2019-242 — capstone: upgrade to the fixed version with the command below.

pip install --upgrade 'capstone>=87a25bb543c8e4c09b48d4b4a6c7db31ce58df06'

Details

Capstone 3.0.4 has an out-of-bounds vulnerability (SEGV caused by a read memory access) in X86_insn_reg_intel in arch/X86/X86Mapping.c.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/capstone
Introduced in: 0Fixed in: 87a25bb543c8e4c09b48d4b4a6c7db31ce58df06
Fixpip install --upgrade 'capstone>=87a25bb543c8e4c09b48d4b4a6c7db31ce58df06'

References