GHSA-9772-cwx9-r4cj

Suggest an improvement
Source
https://github.com/advisories/GHSA-9772-cwx9-r4cj
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-9772-cwx9-r4cj/GHSA-9772-cwx9-r4cj.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9772-cwx9-r4cj
Aliases
Published
2022-05-14T02:05:09Z
Modified
2023-11-01T04:45:41.018078Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
simplejson before 2.6.1 vulnerable to array index error
Details

Array index error in the scanstring function in the json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the rawdecode function.

References

Affected packages

PyPI / simplejson

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.1

Affected versions

1.*

1.1
1.3
1.4
1.5
1.6
1.7
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.8
1.8.1
1.9
1.9.1
1.9.2
1.9.3

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.0.9
2.1.0rc3
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.1.6
2.2.0
2.2.1
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.5.0
2.5.1
2.5.2
2.6.0