CVE-2014-1624

Priority
Description
Race condition in the xdg.BaseDirectory.get_runtime_dir function in
python-xdg 0.25 allows local users to overwrite arbitrary files by
pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a
victim-owned location, then replacing it with a symlink to an
attacker-controlled location once the get_runtime_dir function is called.
Package
Source: pyxdg (LP Ubuntu Debian)
Upstream:needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 ESM (Trusty Tahr):released (0.25-4)
Ubuntu 16.04 LTS (Xenial Xerus):released (0.25-4)
Ubuntu 18.04 LTS (Bionic Beaver):not-affected (0.25-4)
Ubuntu 18.10 (Cosmic Cuttlefish):not-affected (0.25-4)
Ubuntu 19.04 (Disco Dingo):not-affected (0.25-4)
Ubuntu 19.10 (Eoan):not-affected (0.25-4)
More Information

Updated: 2019-05-24 14:14:14 UTC (commit 91b4114344737ff85ab24ef440ef805eefe6c1f9)