Bug 859835 (CVE-2014-1624) - VUL-1: CVE-2014-1624: python-xdg: TOCTOU race condition in get_runtime_dir() when strict=False
Summary: VUL-1: CVE-2014-1624: python-xdg: TOCTOU race condition in get_runtime_dir() ...
Status: RESOLVED FIXED
Alias: CVE-2014-1624
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/95592/
Whiteboard: CVSSv2:NVD:CVE-2014-1624:3.3:(AV:L/AC...
Keywords:
Depends on:
Blocks:
 
Reported: 2014-01-22 09:00 UTC by Sebastian Krahmer
Modified: 2020-05-12 17:40 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Krahmer 2014-01-22 09:00:04 UTC
rh#1056338

CVE-2014-1624

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1056338
Comment 1 Swamp Workflow Management 2014-01-23 23:00:11 UTC
bugbot adjusting priority
Comment 2 Sebastian Krahmer 2014-01-29 09:57:14 UTC
setting VUL-1
Comment 4 Jonathan Kang 2019-09-02 07:16:35 UTC
Fix has been submitted to https://build.suse.de/request/show/200002.
Assign back to security team.
Comment 6 Swamp Workflow Management 2019-10-18 19:16:51 UTC
SUSE-SU-2019:2719-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 859835
CVE References: CVE-2014-1624
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    python-xdg-0.25-9.3.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    python-xdg-0.25-9.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Swamp Workflow Management 2019-11-13 01:03:12 UTC
SUSE-SU-2019:2719-2: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 859835
CVE References: CVE-2014-1624
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    python-xdg-0.25-9.3.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Alexandros Toptsoglou 2020-04-30 12:08:23 UTC
Done