Show plain JSON{"affected_release": [{"advisory": "RHSA-2015:2101", "cpe": "cpe:/o:redhat:enterprise_linux:7", "package": "python-0:2.7.5-34.el7", "product_name": "Red Hat Enterprise Linux 7", "release_date": "2015-11-19T00:00:00Z"}, {"advisory": "RHEA-2014:1175", "cpe": "cpe:/a:redhat:satellite:6.0::el6", "package": "python-anyjson-0:0.3.3-5.el7sat", "product_name": "Red Hat Satellite 6.0", "release_date": "2014-09-10T00:00:00Z"}, {"advisory": "RHEA-2014:1175", "cpe": "cpe:/a:redhat:satellite:6.0::el6", "package": "python-simplejson-0:3.2.0-1.el7sat", "product_name": "Red Hat Satellite 6.0", "release_date": "2014-09-10T00:00:00Z"}, {"advisory": "RHEA-2014:1175", "cpe": "cpe:/a:redhat:satellite_capsule:6.0::el6", "package": "python-anyjson-0:0.3.3-5.el7sat", "product_name": "Red Hat Satellite 6.0", "release_date": "2014-09-10T00:00:00Z"}, {"advisory": "RHEA-2014:1175", "cpe": "cpe:/a:redhat:satellite_capsule:6.0::el6", "package": "python-simplejson-0:3.2.0-1.el7sat", "product_name": "Red Hat Satellite 6.0", "release_date": "2014-09-10T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-0:1.1-17.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-pip-0:1.5.6-5.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-setuptools-0:0.9.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-simplejson-0:3.2.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-wheel-0:0.24.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-0:1.1-17.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-pip-0:1.5.6-5.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-setuptools-0:0.9.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-simplejson-0:3.2.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-wheel-0:0.24.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.5 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-0:1.1-17.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-0:2.7.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-pip-0:1.5.6-5.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-setuptools-0:0.9.8-3.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-simplejson-0:3.2.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el6", "package": "python27-python-wheel-0:0.24.0-2.el6", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 6.6 EUS", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-0:1.1-20.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-0:2.7.8-3.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-pip-0:1.5.6-5.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-setuptools-0:0.9.8-5.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-simplejson-0:3.2.0-3.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}, {"advisory": "RHSA-2015:1064", "cpe": "cpe:/a:redhat:rhel_software_collections:2::el7", "package": "python27-python-wheel-0:0.24.0-2.el7", "product_name": "Red Hat Software Collections for Red Hat Enterprise Linux 7", "release_date": "2015-06-04T00:00:00Z"}], "bugzilla": {"description": "python: missing boundary check in JSON module", "id": "1112285", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1112285"}, "csaw": false, "cvss": {"cvss_base_score": "4.0", "cvss_scoring_vector": "AV:N/AC:H/Au:N/C:P/I:N/A:P", "status": "verified"}, "cwe": "CWE-129->CWE-119", "details": ["Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.", "A flaw was found in the way the json module handled negative index argument passed to certain functions (such as raw_decode()). An attacker able to control index value passed to one of the affected functions could possibly use this flaw to disclose portions of the application memory."], "name": "CVE-2014-4616", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Not affected", "package_name": "python", "product_name": "Red Hat Enterprise Linux 5"}, {"cpe": "cpe:/o:redhat:enterprise_linux:5", "fix_state": "Will not fix", "package_name": "python-simplejson", "product_name": "Red Hat Enterprise Linux 5"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Not affected", "package_name": "python", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Will not fix", "package_name": "python-simplejson", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/a:redhat:openstack:5::el7", "fix_state": "Affected", "package_name": "python-simplejson", "product_name": "Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:1", "fix_state": "Affected", "package_name": "python27-python", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:1", "fix_state": "Affected", "package_name": "python27-python-simplejson", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:2", "fix_state": "Will not fix", "package_name": "python33-python", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:2", "fix_state": "Will not fix", "package_name": "python33-python-simplejson", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:2", "fix_state": "Not affected", "package_name": "rh-python34-python", "product_name": "Red Hat Software Collections"}], "public_date": "2014-05-19T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2014-4616\nhttps://nvd.nist.gov/vuln/detail/CVE-2014-4616"], "statement": "This issue affects the versions of python as shipped with Red Hat Enterprise Linux 7, the versions of python-simplejson as shipped with Red Hat Enterprise Linux 5 and 6, and the versions of python33-python and python33-python-simplejson as shipped with Red Hat Software Collections. Red Hat Product Security has rated this issue as having Moderate security impact. Future updates may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.", "threat_severity": "Moderate"}