CVE-2014-1624
Publication date 28 January 2014
Last updated 29 August 2025
Ubuntu priority
Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
Status
Package | Ubuntu Release | Status |
---|---|---|
pyxdg | ||
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Fixed 0.25-4
|
|
14.04 LTS trusty |
Fixed 0.25-4
|
|