CVE-2014-1604
RPLY < 0.7.1 - Cache Spoofing via Predictable Temporary File
Title source: llmDescription
The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.
References (7)
Core 7
Core References
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/17/8
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90593
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://www.osvdb.org/102202
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/56429
Patch x_refsource_confirm
https://github.com/alex/rply/commit/fc9bbcd25b0b4f09bbd6339f710ad24c129d5d7c
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=735263
Mailing List mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/18/4
Scores
EPSS
0.0007
EPSS Percentile
22.2%
Details
Status
published
Products (2)
pypi/rply
0 - 0.7.1PyPI
python/rply
< 0.7.0
Published
Jan 28, 2014
Tracked Since
Feb 18, 2026