PT-2014-6024 · Bob Ippolito+5 · Simplejson+5

Publicado

2014-06-26

·

Atualizado

2022-07-13

·

CVE-2014-4616

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Python versions 2.7 through 3.5 simplejson versions prior to 2.6.1
Description The issue is related to an array index error in the scanstring function in the json module. This error allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw decode function.
Recommendations For Python versions 2.7 through 3.5, update to a version later than 3.5 to resolve the issue. For simplejson versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue.

Exploit

Correção

Improper Validation of Array Index

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-2376
ALT-PU-2016-1294
CESA-2015_2101
CVE-2014-4616
GHSA-9772-CWX9-R4CJ
MGASA-2014-0285
MGASA-2014-0286
PSF-2017-1
RHSA-2015:1064
RHSA-2015:2101
RHSA-2015_2101
USN-2653-1

Produtos afetados

Alt Linux
Centos
Python
Red Hat
Ubuntu
Simplejson