CVE-2014-1624

Source
https://cve.org/CVERecord?id=CVE-2014-1624
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2014-1624.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2014-1624
Aliases
Downstream
Related
Published
2014-01-28T00:55:04Z
Modified
2026-04-10T03:44:37.533389Z
Summary
[none]
Details

Race condition in the xdg.BaseDirectory.getruntimedir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the getruntimedir function is called.

References

Affected packages