Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-4616

Опубликовано: 19 мая 2014
Источник: redhat
CVSS2: 4
EPSS Низкий

Описание

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

A flaw was found in the way the json module handled negative index argument passed to certain functions (such as raw_decode()). An attacker able to control index value passed to one of the affected functions could possibly use this flaw to disclose portions of the application memory.

Отчет

This issue affects the versions of python as shipped with Red Hat Enterprise Linux 7, the versions of python-simplejson as shipped with Red Hat Enterprise Linux 5 and 6, and the versions of python33-python and python33-python-simplejson as shipped with Red Hat Software Collections. Red Hat Product Security has rated this issue as having Moderate security impact. Future updates may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5pythonNot affected
Red Hat Enterprise Linux 5python-simplejsonWill not fix
Red Hat Enterprise Linux 6pythonNot affected
Red Hat Enterprise Linux 6python-simplejsonWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7python-simplejsonAffected
Red Hat Software Collectionspython27-pythonAffected
Red Hat Software Collectionspython27-python-simplejsonAffected
Red Hat Software Collectionspython33-pythonWill not fix
Red Hat Software Collectionspython33-python-simplejsonWill not fix
Red Hat Software Collectionsrh-python34-pythonNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-129->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1112285python: missing boundary check in JSON module

EPSS

Процентиль: 60%
0.00398
Низкий

4 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 8 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
nvd
почти 8 лет назад

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

CVSS3: 5.9
debian
почти 8 лет назад

Array index error in the scanstring function in the _json module in Py ...

CVSS3: 5.9
github
около 3 лет назад

simplejson before 2.6.1 vulnerable to array index error

oracle-oval
больше 9 лет назад

ELSA-2015-2101: python security, bug fix, and enhancement update (MODERATE)

EPSS

Процентиль: 60%
0.00398
Низкий

4 Medium

CVSS2