CVE-2014-4616Medium· 5.9▾ Sunlitsimplejson before 2.6.1 vulnerable to array index error
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 1.6 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
8.1%
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
simplejson < 2.6.1Upgrade to a patched release:
simplejson 2.6.1