{"id":"CVE-2014-1624","aliases":["GHSA-7372-q459-jxhr","PYSEC-2014-95"],"url":"https://o3.security/vulnerability/CVE-2014-1624","summary":"pyxdg Arbitrary File Overwrite via Race Condition","details":"Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.","published":"2014-01-28T00:55:04Z","modified":"2026-04-10T03:44:37.533389Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"pyxdg","fixedVersion":"0.26"}],"fix":null,"references":[{"type":"WEB","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736247"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/01/21/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/01/21/4"},{"type":"WEB","url":"http://www.securityfocus.com/bid/65042"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/90618"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-10T03:44:37.533389Z"}}