Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-1888

Опубликовано: 17 авг. 2013
Источник: debian
EPSS Низкий

Описание

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pipnot-affectedpackage

Примечания

  • https://github.com/pypa/pip/pull/780/files

  • Not-affected as vulnerable code only in 1.3, and 1.3.1-1 fixed the issue.

EPSS

Процентиль: 30%
0.00367
Низкий

Связанные уязвимости

ubuntu
около 13 лет назад

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

nvd
около 13 лет назад

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

CVSS3: 6.2
github
больше 4 лет назад

Improper Link Resolution Before File Access in pip

EPSS

Процентиль: 30%
0.00367
Низкий