CVE-2014-1604

RPLY < 0.7.1 - Cache Spoofing via Predictable Temporary File

Title source: llm
STIX 2.1

Description

The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.

References (7)

Core 7
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/17/8
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90593
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/102202
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/56429
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=735263
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/18/4

Scores

EPSS 0.0007
EPSS Percentile 22.2%

Details

Status published
Products (2)
pypi/rply 0 - 0.7.1PyPI
python/rply < 0.7.0
Published Jan 28, 2014
Tracked Since Feb 18, 2026