[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Python-xdg - (bulletinjan2017)

ID: oval:org.secpod.oval:def:2100731Date: (C)2019-12-31   (M)2022-10-10
Class: PATCHFamily: unix




Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.

Platform:
Sun Solaris 11
Product:
library/python/python-xdg-27
Reference:
bulletinjan2017
CVE-2014-1624
CVE    1
CVE-2014-1624
CPE    1
cpe:/o:oracle:solaris:11

© SecPod Technologies