CVE-2014-4616

Published: 26 June 2014

Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.

Priority

Low

CVSS 3 base score: 5.9

Status

Package Release Status
python2.7
Launchpad, Ubuntu, Debian
Upstream Not vulnerable
(2.7.7~rc1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (2.7.6-8ubuntu0.2)
Patches:
Upstream: http://hg.python.org/cpython/rev/50c07ed1743d
Upstream: https://hg.python.org/cpython/rev/4bd1fb0f4f44
Upstream: https://hg.python.org/cpython/rev/c7b93519807a
python3.2
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 14.04 ESM (Trusty Tahr) Does not exist

python3.4
Launchpad, Ubuntu, Debian
Upstream
Released (3.4.1)
Ubuntu 14.04 ESM (Trusty Tahr)
Released (3.4.0-2ubuntu1.1)
Patches:
Upstream: http://hg.python.org/cpython/rev/7b95540ced5c/
Upstream: https://hg.python.org/cpython/rev/ef52ae167555