Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-8991

Опубликовано: 24 нояб. 2014
Источник: debian

Описание

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-pipfixed1.5.6-4package
python-pipnot-affectedwheezypackage
python-pipnot-affectedsqueezepackage

Примечания

  • https://github.com/pypa/pip/pull/2122

Связанные уязвимости

ubuntu
около 11 лет назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

redhat
около 12 лет назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

nvd
около 11 лет назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

msrc
4 месяца назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

CVSS3: 6.2
github
больше 3 лет назад

pip lack of randomness in build directory