Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-4616

Опубликовано: 24 авг. 2017
Источник: debian
EPSS Низкий

Описание

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python2.5removedpackage
python2.5no-dsasqueezepackage
python2.6removedpackage
python2.6no-dsasqueezepackage
python2.6no-dsawheezypackage
python2.7fixed2.7.7-1package
python2.7no-dsawheezypackage
python3.2removedpackage
python3.2no-dsawheezypackage
python3.3removedpackage
python3.4fixed3.4.0+20140417-1package

Примечания

  • http://bugs.python.org/issue21529

EPSS

Процентиль: 61%
0.00411
Низкий

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 8 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

redhat
около 11 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
nvd
почти 8 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
github
около 3 лет назад

simplejson before 2.6.1 vulnerable to array index error

oracle-oval
больше 9 лет назад

ELSA-2015-2101: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 61%
0.00411
Низкий