{"id":"DEBIAN-CVE-2014-1624","details":"Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.","modified":"2026-09-01T20:03:20.560995362Z","published":"2014-01-28T00:55:04.083Z","upstream":["CVE-2014-1624"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2014-1624"}],"affected":[{"package":{"name":"pyxdg","ecosystem":"Debian:12","purl":"pkg:deb/debian/pyxdg?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.25-4"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-1624.json"}},{"package":{"name":"pyxdg","ecosystem":"Debian:13","purl":"pkg:deb/debian/pyxdg?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.25-4"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-1624.json"}},{"package":{"name":"pyxdg","ecosystem":"Debian:14","purl":"pkg:deb/debian/pyxdg?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.25-4"}]}],"ecosystem_specific":{"urgency":"low"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2014-1624.json"}}],"schema_version":"1.9.0"}