CVE-2014-1624
Publication date 28 January 2014
Last updated 23 September 2025
Ubuntu priority
Description
Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| pyxdg | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Fixed 0.25-4
|
|
| 14.04 LTS trusty |
Fixed 0.25-4
|
|