CVE-2014-4616: Opensuse
Medium severity, CVSS 5.9. EPSS: 8.1% chance of exploitation in the next 30 days.
Array index error in the scanstring function in the _json module in Python 2.7 through 3.5 and simplejson before 2.6.1 allows context-dependent attackers to read arbitrary process memory via a negative index value in the idx argument to the raw_decode function.
Affected products
- Opensuse Opensuse: version 13.1 only
- Opensuse Project Opensuse: version 12.3 only
- Python Python: from 2.7.0, before 2.7.7 (fixed in 2.7.7); from 3.0.0, before 3.2.6 (fixed in 3.2.6); from 3.3.0, before 3.3.6 (fixed in 3.3.6); from 3.4.0, before 3.4.1 (fixed in 3.4.1)
- Simplejson Project Simplejson: before 2.6.1 (fixed in 2.6.1)
Published 2017-08-24. Last modified 2026-06-17.