pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade py-pip. | Aug 30, 2017 | Nov 24, 2014 |
| Debian | — | Upgrade python-pip | Jul 30, 2024 | Nov 24, 2014 |
| Oracle Solaris | — | Upgrade library/python-2/pip-26 to version 6.0.8-0.175.2.12.0.3.0 on Solaris 11.2Upgrade library/python-2/pip to version 6.0.8-0.175.2.12.0.3.0 on Solaris 11.2Upgrade library/python-2/pip-27 to version 6.0.8-0.175.2.12.0.3.0 on Solaris 11.2 | May 29, 2017 | Nov 24, 2014 |
| Suse | — | Upgrade python3-pip-wheelUpgrade python-paramikoUpgrade python39-pipUpgrade python3-jsonschemaUpgrade python-jmespathUpgrade python3-jmespathUpgrade python39-setuptoolsUpgrade python-plyUpgrade python3-paramikoUpgrade python-pipUpgrade python3-plyUpgrade python3-pipUpgrade python-jsonschemaUpgrade python2-pip | Dec 9, 2016 | Nov 24, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub