CVE-2019-12760
Summary
| CVE | CVE-2019-12760 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-06 19:29:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | ** DISPUTED ** A deserialization vulnerability exists in the way parso through 0.4.0 handles grammar parsing from the cache. Cache loading relies on pickle and, provided that an evil pickle can be written to a cache grammar file and that its parsing can be triggered, this flaw leads to Arbitrary Code Execution. NOTE: This is disputed because "the cache directory is not under control of the attacker in any common configuration." |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Parso Project |
Parso |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Proof-of-Concept for Python parso Cache Load Vulnerability (CVE-2019-12760) · GitHub |
MISC |
gist.github.com |
Exploit, Third Party Advisory |
| Deserialization vulnerability (CVE-2019-12760) · Issue #75 · davidhalter/parso · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983478 Python (pip) Security Update for parso (GHSA-22mf-97vh-x8rw)