PYSEC-2014-95
Dashboard / Vulnerabilities / PYSEC-2014-95
PYSEC-2014-95
Summary:
Details: Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
References: http://www.openwall.com/lists/oss-security/2014/01/21/4, http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736247, http://www.openwall.com/lists/oss-security/2014/01/21/3, http://www.securityfocus.com/bid/65042, https://exchange.xforce.ibmcloud.com/vulnerabilities/90618, https://github.com/advisories/GHSA-7372-q459-jxhr
Affected packages
Package
Name: pyxdg
Purl: pkg:pypi/pyxdg
Affected ranges
Type: ECOSYSTEM
Events:
