Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
2014-01-28T00:55:04.083
2025-04-11T00:51:21.963
Deferred
CVSSv2: 3.3 (LOW)
AV:L/AC:M/Au:N/C:N/I:P/A:P
3.4
4.9