Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-1624

Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.3%
CVSS Severity
CVSS v2 Score 3.3
Products affected by CVE-2014-1624
  • Python » Pyxdg » Version: 0.25
    cpe:2.3:a:python:pyxdg:0.25


Contact Us

Shodan ® - All rights reserved