ALT-PU-2025-3664-3
Package python-module-pyxdg updated to version 0.26-alt1 for branch c9f2 in task 376385.
Closed vulnerabilities
BDU:2021-05299
Уязвимость библиотеки языка программирования Python pyxdg, связанная с неверным управлением генерацией кода, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2014-1624
Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736247
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=736247
- [oss-security] 20140121 Fwd: [Python-modules-team] Bug#736247: python-xdg: get_runtime_dir(strict=False): insecure use of /tmp
- [oss-security] 20140121 Fwd: [Python-modules-team] Bug#736247: python-xdg: get_runtime_dir(strict=False): insecure use of /tmp
- [oss-security] 20140121 Re: Fwd: [Python-modules-team] Bug#736247: python-xdg: get_runtime_dir(strict=False): insecure use of /tmp
- [oss-security] 20140121 Re: Fwd: [Python-modules-team] Bug#736247: python-xdg: get_runtime_dir(strict=False): insecure use of /tmp
- 65042
- 65042
- pythonxdg-cve20141624-symlink(90618)
- pythonxdg-cve20141624-symlink(90618)
Modified: 2024-11-21
CVE-2019-12761
A code injection issue was discovered in PyXDG before 0.26 via crafted Python code in a Category element of a Menu XML document in a .menu file. XDG_CONFIG_DIRS must be set up to trigger xdg.Menu.parse parsing within the directory containing this file. This is due to a lack of sanitization in xdg/Menu.py before an eval call.
- https://gist.github.com/dhondta/b45cd41f4186110a354dc7272916feba
- https://gist.github.com/dhondta/b45cd41f4186110a354dc7272916feba
- [debian-lts-announce] 20190616 [SECURITY] [DLA 1819-1] pyxdg security update
- [debian-lts-announce] 20190616 [SECURITY] [DLA 1819-1] pyxdg security update
- [debian-lts-announce] 20210803 [SECURITY] [DLA 2727-1] pyxdg security update
- [debian-lts-announce] 20210803 [SECURITY] [DLA 2727-1] pyxdg security update
- https://snyk.io/vuln/SNYK-PYTHON-PYXDG-174562
- https://snyk.io/vuln/SNYK-PYTHON-PYXDG-174562