CVE-2014-1604: RPLY Predictable Tmpfile Names Allows Cache Spoofing
(updated )
The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.
References
- exchange.xforce.ibmcloud.com/vulnerabilities/90593
- github.com/advisories/GHSA-9gcf-pq99-rjw3
- github.com/alex/rply/commit/fc9bbcd25b0b4f09bbd6339f710ad24c129d5d7c
- github.com/pypa/advisory-database/tree/main/vulns/rply/PYSEC-2014-117.yaml
- github.com/pypa/advisory-database/tree/main/vulns/rply/PYSEC-2014-17.yaml
- nvd.nist.gov/vuln/detail/CVE-2014-1604
Code Behaviors & Features
Detect and mitigate CVE-2014-1604 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →