PT-2013-3451 · Python · Pip

D1B

+2

·

Published

2013-08-16

·

Updated

2022-05-13

·

CVE-2013-1888

CVSS v4.0

6.9

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pip versions prior to 1.3
Description The issue allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
Recommendations For versions prior to 1.3, update to version 1.3 or later to resolve the issue.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-1888
GHSA-4GV5-QHVR-36VV
PYSEC-2013-9

Affected Products

Pip