« Volver al listado

CVE-2014-2667

Estado: ModificadaBaja (3.3)—

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-2667",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-11-16T01:59:01.927",
  "references": [
    {
      "url": "http://bugs.python.org/issue21082",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00007.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/28/15",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/29/5",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/30/4",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.gentoo.org/glsa/201503-10",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.python.org/issue21082",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00040.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00007.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-updates/2014-05/msg00008.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/28/15",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/29/5",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/03/30/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.gentoo.org/glsa/201503-10",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-362"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value."
    },
    {
      "lang": "es",
      "value": "Condición de carrera en la función _get_masked_mode en Lib/os.py en Python 3.2 hasta 3.5, cuando exist_ok está activado y se utilizan múltiples hilos, podría permitir a usuarios locales saltarse el archivo destinado a los permisos aprovechando una vulnerabilidad de solicitud por separado antes de que umask haya sido ajustado al valor esperado."
    }
  ],
  "lastModified": "2026-06-17T00:06:59.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:python:python:3.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B511BDFA-D1DC-4E50-9A08-66DA05947A43"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0708E98D-5C84-47DC-89E5-8BB7CFFB12A7"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6595C4F3-5683-4889-AD30-83840F6A58D1"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "027FD902-9B08-4EDF-9F83-314FBF0583ED"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89FB9D30-8559-4F57-9D20-DC603765B346"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "957FCB4A-32D0-4449-8995-80144CC713B4"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C17A0E8D-7611-42F7-896E-F2B3BC25643D"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "875ABC97-2783-41DA-AB9F-9E6F0870B74C"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5262D28D-204C-41E8-BC4D-27372E366295"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "121225D0-C5DA-4F26-93B8-3D56BC1D38B1"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52DD66F7-FE7B-4C1C-B07B-F9E4CEEA7AFD"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6C2C18A1-F202-4E48-8E29-F250AD1A6737"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EE1602B-6ECB-492B-BFEB-21AF40EE4A4A"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.3.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "64662850-7460-46C2-852E-E047874F9660"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D6658A8-E57E-4743-95D5-074F990D0D1B"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6C65BBA-4DC7-4F2F-90B1-75C6F3C68FBE"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D0DBAEE-599A-44EB-A1E4-94CEBB406CAE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}