2.1
CVSSv2

CVE-2014-8991

Published: 24/11/2014 Updated: 15/03/2021
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

pip 1.3 up to and including 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pypa pip

oracle solaris 11.2

Vendor Advisories

Debian Bug report logs - #725847 python-pip: CVE-2014-8991: DoS by other users on the same system Package: python-pip; Maintainer for python-pip is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Source for python-pip is src:python-pip (PTS, buildd, popcon) Reported by: Paul Wise <pabs@debianorg ...
pip 13 through 156 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user ...