GHSA-7372-q459-jxhr
Dashboard / Vulnerabilities / GHSA-7372-q459-jxhr
GHSA-7372-q459-jxhr
Summary: pyxdg Arbitrary File Overwrite via Race Condition
Details: Race condition in the `xdg.BaseDirectory.get_runtime_dir` function in pyxdg 0.25 allows local users to overwrite arbitrary files by pre-creating `/tmp/pyxdg-runtime-dir-fallback-victim` to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the `get_runtime_dir` function is called.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-1624, https://github.com/takluyver/pyxdg/commit/bd999c1c3fe7ee5f30ede2cf704cf03e400347b4, https://exchange.xforce.ibmcloud.com/vulnerabilities/90618, https://github.com/pypa/advisory-database/tree/main/vulns/pyxdg/PYSEC-2014-95.yaml, https://github.com/takluyver/pyxdg, https://web.archive.org/web/20200227194825/http://www.securityfocus.com/bid/65042, http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736247, http://www.openwall.com/lists/oss-security/2014/01/21/3, http://www.openwall.com/lists/oss-security/2014/01/21/4
Affected packages
Package
Name: pyxdg
Purl: pkg:pypi/pyxdg
Affected ranges
Type: ECOSYSTEM
Events:
