CVE-2014-1839
The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0006 (0.1%)
Percentile: 18.9%
EPSS: 2026-05-06
Affects
opensuse:opensuselogilab:logilab-commonTechnical description
The Execute class in shellutils in logilab-commons before 0.61.0 uses tempfile.mktemp, which allows local users to have an unspecified impact by pre-creating the temporary file.
Published: 3/11/2014, 7:37:04 PM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://comments.gmane.org/gmane.comp.security.oss.general/11986
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html
- http://secunia.com/advisories/57209
- http://www.logilab.org/ticket/207562
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737051
- http://comments.gmane.org/gmane.comp.security.oss.general/11986
- http://lists.opensuse.org/opensuse-updates/2014-02/msg00085.html
- http://secunia.com/advisories/57209