Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Python | Python | 2.7.0 (including) | 2.7.7 (excluding) |
Python | Python | 3.0.0 (including) | 3.2.6 (excluding) |
Python | Python | 3.3.0 (including) | 3.3.6 (excluding) |
Python | Python | 3.4.0 (including) | 3.4.1 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | python-0:2.7.5-34.el7 | * |
Red Hat Satellite 6.0 | RedHat | python-anyjson-0:0.3.3-5.el7sat | * |
Red Hat Satellite 6.0 | RedHat | python-simplejson-0:3.2.0-1.el7sat | * |
Red Hat Satellite 6.0 | RedHat | python-anyjson-0:0.3.3-5.el7sat | * |
Red Hat Satellite 6.0 | RedHat | python-simplejson-0:3.2.0-1.el7sat | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-0:1.1-17.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-0:2.7.8-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-pip-0:1.5.6-5.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-setuptools-0:0.9.8-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-simplejson-0:3.2.0-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6 | RedHat | python27-python-wheel-0:0.24.0-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | RedHat | python27-0:1.1-17.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | RedHat | python27-python-0:2.7.8-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | RedHat | python27-python-pip-0:1.5.6-5.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | RedHat | python27-python-setuptools-0:0.9.8-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | RedHat | python27-python-simplejson-0:3.2.0-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS | RedHat | python27-python-wheel-0:0.24.0-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-0:1.1-17.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-python-0:2.7.8-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-python-pip-0:1.5.6-5.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-python-setuptools-0:0.9.8-3.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-python-simplejson-0:3.2.0-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS | RedHat | python27-python-wheel-0:0.24.0-2.el6 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-0:1.1-20.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-0:2.7.8-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-pip-0:1.5.6-5.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-setuptools-0:0.9.8-5.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-simplejson-0:3.2.0-3.el7 | * |
Red Hat Software Collections for Red Hat Enterprise Linux 7 | RedHat | python27-python-wheel-0:0.24.0-2.el7 | * |
Python2.7 | Ubuntu | precise | * |
Python2.7 | Ubuntu | saucy | * |
Python2.7 | Ubuntu | trusty | * |
Python3.2 | Ubuntu | precise | * |
Python3.4 | Ubuntu | trusty | * |
Python3.4 | Ubuntu | upstream | * |