CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:L/AC:M/Au:N/C:N/I:P/A:P
EPSS
Percentile
5.1%
Race condition in the xdg.BaseDirectory.get_runtime_dir function in
python-xdg 0.25 allows local users to overwrite arbitrary files by
pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a
victim-owned location, then replacing it with a symlink to an
attacker-controlled location once the get_runtime_dir function is called.