VDB
KO

PYSEC-2014-117

Details

The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / rply

No fixed version published yet for rply (pip). Pin to a known-safe version or switch to an alternative.

References