Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2014-2667

LOW severity · CVSS 3.3 · CWE-362
3.3CVSS LOW

Summary

Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.

Impact & exploitability

Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impactNone
Exploit probability (EPSS)0%

AV:L/AC:M/Au:N/C:P/I:P/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.