{"id":"CVE-2020-10174","details":"init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can attempt to win a race condition to replace scripts created by Timeshift with attacker-controlled scripts. Upon success, an attacker-controlled script is executed with full root privileges. This logic is practically always triggered when Timeshift runs regardless of the command-line arguments used.","modified":"2026-07-08T05:55:36.242489705Z","published":"2020-03-05T16:15:11.940Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"19.10"},{"last_affected":"19.10"}],"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"]},{"vendor_product":"fedoraproject:fedora","cpes":["cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"30"},{"last_affected":"30"},{"introduced":"31"},{"last_affected":"31"},{"introduced":"32"},{"last_affected":"32"}],"source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AAOFXT64CEUMJE3723JDJWTEQWQUCYMD/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SXDEPC52G46U6I7GLQNFLZXVSM7V2HYY/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TXXYQFSZ5P6ZMNFIDBAQKBFZIR2T7ZLL/"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2020/03/06/3"},{"type":"ADVISORY","url":"https://github.com/teejee2008/timeshift/releases/tag/v20.03"},{"type":"ADVISORY","url":"https://usn.ubuntu.com/4312-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1165802"},{"type":"FIX","url":"https://github.com/teejee2008/timeshift/commit/335b3d5398079278b8f7094c77bfd148b315b462"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/teejee2008/timeshift","events":[{"introduced":"0"},{"fixed":"cecd294dcaea9bcf282865268dc6667fbeeeddb3"},{"fixed":"335b3d5398079278b8f7094c77bfd148b315b462"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:timeshift_project:timeshift:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"20.03"}]}}],"versions":["v19.08.1","v19.01","v18.9.1","v18.9","v18.8","v18.6.1","v18.6","v18.4","v18.2","v18.1.1","v18.1","v17.11","v17.10","v17.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-10174.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}