Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8991

Опубликовано: 09 окт. 2013
Источник: redhat
CVSS2: 2.1
EPSS Низкий

Описание

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1python-virtualenvUnder investigation
Red Hat Enterprise Linux 7python-virtualenvUnder investigation
Red Hat OpenShift Enterprise 2python27-python-pipUnder investigation
Red Hat OpenShift Enterprise 2python-virtualenvUnder investigation
Red Hat Software Collections for Red Hat Enterprise Linuxpython27-python-virtualenvUnder investigation
Red Hat Software Collections for Red Hat Enterprise Linuxpython33-python-virtualenvUnder investigation

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-377
https://bugzilla.redhat.com/show_bug.cgi?id=1166137python-pip: local DoS vulnerability

EPSS

Процентиль: 22%
0.00072
Низкий

2.1 Low

CVSS2

Связанные уязвимости

ubuntu
около 11 лет назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

nvd
около 11 лет назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

msrc
4 месяца назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

debian
около 11 лет назад

pip 1.3 through 1.5.6 allows local users to cause a denial of service ...

CVSS3: 6.2
github
больше 3 лет назад

pip lack of randomness in build directory

EPSS

Процентиль: 22%
0.00072
Низкий

2.1 Low

CVSS2