SWHKD is a display protocol-independent hotkey daemon made in Rust. In SWHKD versions 1.1.5 and prior, SWHKD uses the /tmp/swhkd.pid pathname. As /tmp is accessible to all users, there can be an information leak or denial of service. No known workarounds exist. A patch is available on the 1.1.0
branch of the repository.
{ "nvd_published_at": "2022-03-30T00:15:00Z", "github_reviewed_at": "2022-04-01T15:15:36Z", "severity": "CRITICAL", "github_reviewed": true, "cwe_ids": [ "CWE-377", "CWE-59" ] }