A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-06-06T18:55:03
Updated: 2024-08-04T23:32:54.763Z
Reserved: 2019-06-06T00:00:00
Link: CVE-2019-12760
Vulnrichment
Updated: 2024-08-04T23:32:54.763Z
NVD
Status : Modified
Published: 2019-06-06T19:29:00.500
Modified: 2024-08-05T00:15:29.170
Link: CVE-2019-12760
Redhat
No data.