Python JSON Module '_json.c' Local Information Disclosure Vulnerability
BID:68119
CVE-2014-4616 |Info
Python JSON Module '_json.c' Local Information Disclosure Vulnerability
| Bugtraq ID: | 68119 |
| Class: | Design Error |
| CVE: |
CVE-2014-4616 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 20 2014 12:00AM |
| Updated: | Jul 06 2016 02:08PM |
| Credit: | Guido Vranken |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Python Software Foundation Python 3.3 Python Software Foundation Python 3.2 Python Software Foundation Python 3.1 Oracle Linux 0 |
| Not Vulnerable: | |
Discussion
Python JSON Module '_json.c' Local Information Disclosure Vulnerability
Python is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information. Information obtained may lead to further attacks.
Python is prone to a local information-disclosure vulnerability.
Local attackers can exploit this issue to obtain sensitive information. Information obtained may lead to further attacks.
Exploit / POC
Python JSON Module '_json.c' Local Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Python JSON Module '_json.c' Local Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva lib64python-devel-2.7.3-4.7.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64python2.7-2.7.3-4.7.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva python-2.7.3-4.7.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva python-docs-2.7.3-4.7.mbs1.noarch.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva python-simplejson-2.3.3-2.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tkinter-2.7.3-4.7.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva tkinter-apps-2.7.3-4.7.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
Python JSON Module '_json.c' Local Information Disclosure Vulnerability
References:
References:
- Bug 1112285 - python: missing boundary check in JSON module (Red Hat Bugzilla)
- Debian Bug report logs - #752395 python2.7: JSON module: reading arbitrary proce (Gert van Dijk)
- JSON module: reading arbitrary process memory (Python Software Foundation)
- Python Homepage (Python Software Foundation)
- Python vulnerability: reading arbitrary process memory (Python)
- isg3T1023439: Multiple vulnerabilities in Python affect PowerKVM (IBM)
- Oracle Linux Bulletin - January 2016 (Oracle)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- RHSA-2015:1064-1 (RedHat)