CVE-2014-1624

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
28/01/2014
Last modified:
11/04/2025

Description

Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:python:pyxdg:0.25:*:*:*:*:*:*:*