Executive brief
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
Affected products
- PyPI pip
Junglewise Threat Intelligence
CVE-2014-8991 · Severity: low · CVSS 3.1 · Published 2014-11-24
Technologies: pip (PyPI). Vendors: PyPI.
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.