PT-2014-4263 · Python+2 · Python-Xdg+2

Published

2014-01-28

·

Updated

2025-03-06

·

CVE-2014-1624

CVSS v2.0

3.3

Low

VectorAV:L/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions python-xdg version 0.25
Description A race condition exists in the xdg.BaseDirectory.get runtime dir function, allowing local users to overwrite arbitrary files. This is achieved by pre-creating a file to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get runtime dir function is called.
Recommendations For python-xdg version 0.25, consider disabling the xdg.BaseDirectory.get runtime dir function until a patch is available to prevent exploitation. Restrict access to the /tmp/pyxdg-runtime-dir-fallback-victim location to minimize the risk of arbitrary file overwrites. Avoid using the get runtime dir function in sensitive operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-3664
CVE-2014-1624
GHSA-7372-Q459-JXHR
PYSEC-2014-95
SUSE-SU-2019:2719-1
SUSE-SU-2019:2719-2
SUSE-SU-2019_2719-1
SUSE-SU-2019_2719-2

Affected Products

Alt Linux
Suse
Python-Xdg