Description
Race condition in the _get_masked_mode function in Lib/os.py in Python 3.2 through 3.5, when exist_ok is set to true and multiple threads are used, might allow local users to bypass intended file permissions by leveraging a separate application vulnerability before the umask has been set to the expected value.
Remediation
References
Related Vulnerabilities
WordPress Plugin DukaPress Multiple Cross-Site Scripting Vulnerabilities (2.5.9)
WordPress Plugin Jetpack-WP Security, Backup, Speed, & Growth Security Bypass (2.9.2)
PHP Other Vulnerability (CVE-2015-6838)
Django CVE-2024-24680 Vulnerability (CVE-2024-24680)
WordPress Plugin 404 to 301-Redirect, Log and Notify 404 Errors Cloaking (2.2.9)