CVE-2014-1624

Priority
Low
Description
Race condition in the xdg.BaseDirectory.get_runtime_dir function in
python-xdg 0.25 allows local users to overwrite arbitrary files by
pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a
victim-owned location, then replacing it with a symlink to an
attacker-controlled location once the get_runtime_dir function is called.
References
Bugs
Package
Source: pyxdg (LP Ubuntu Debian)
Upstream:needed
Ubuntu 17.10 (Artful Aardvark):needed
Ubuntu 12.04 ESM (Precise Pangolin):DNE (precise was needed)
Ubuntu 14.04 LTS (Trusty Tahr):needed
Ubuntu 16.04 LTS (Xenial Xerus):needed
Ubuntu 17.04 (Zesty Zapus):needed
More Information

Updated: 2017-10-17 19:14:07 UTC (commit 13537)