CVE-2014-1624
28.01.2014, 00:55
Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
Link Following
Vendor | Product | Version |
---|---|---|
python | pyxdg | 0.25 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References