PT-2014-6024 · Bob Ippolito+5 · Simplejson+5

Published

2014-06-26

·

Updated

2022-07-13

·

CVE-2014-4616

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Python versions 2.7 through 3.5 simplejson versions prior to 2.6.1
Description The issue is related to an array index error in the scanstring function in the json module. This error allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw decode function.
Recommendations For Python versions 2.7 through 3.5, update to a version later than 3.5 to resolve the issue. For simplejson versions prior to 2.6.1, update to version 2.6.1 or later to resolve the issue.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2376
ALT-PU-2016-1294
CESA-2015_2101
CVE-2014-4616
GHSA-9772-CWX9-R4CJ
MGASA-2014-0285
MGASA-2014-0286
PSF-2017-1
RHSA-2015:1064
RHSA-2015:2101
RHSA-2015_2101
USN-2653-1

Affected Products

Alt Linux
Centos
Python
Red Hat
Ubuntu
Simplejson