Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-2667

Опубликовано: 16 нояб. 2014
Источник: debian
EPSS Низкий

Описание

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python3.1removedpackage
python3.1no-dsasqueezepackage
python3.2removedpackage
python3.2no-dsawheezypackage
python3.3removedpackage
python3.4fixed3.4.1-1package
python2.5not-affectedpackage
python2.6not-affectedpackage
python2.7not-affectedpackage

EPSS

Процентиль: 14%
0.00046
Низкий

Связанные уязвимости

ubuntu
больше 10 лет назад

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

redhat
около 11 лет назад

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

nvd
больше 10 лет назад

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

github
около 3 лет назад

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

suse-cvrf
больше 5 лет назад

Security update for python3

EPSS

Процентиль: 14%
0.00046
Низкий