—
PYSEC-2014-95
Quick fix
PYSEC-2014-95 — pyxdg: upgrade to the fixed version with the command below.
pip install --upgrade 'pyxdg>=0.26'Details
Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- http://www.openwall.com/lists/oss-security/2014/01/21/4[WEB]
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736247[WEB]
- http://www.openwall.com/lists/oss-security/2014/01/21/3[WEB]
- http://www.securityfocus.com/bid/65042[WEB]
- https://exchange.xforce.ibmcloud.com/vulnerabilities/90618[WEB]
- https://github.com/advisories/GHSA-7372-q459-jxhr[ADVISORY]