First published: Fri Aug 16 2013(Updated: )
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/pip | <1.3 | 1.3 |
pip/pywasm3 | <1.3 | |
Fedora | =17 | |
Fedora | =18 | |
Fedora | =19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1888 is considered a moderate severity vulnerability due to its potential for local users to gain unauthorized access to files.
To fix CVE-2013-1888, upgrade pip to version 1.3 or higher.
CVE-2013-1888 affects versions of pip before 1.3.
CVE-2013-1888 requires local access, so it cannot be exploited remotely.
CVE-2013-1888 impacts Fedora versions 17, 18, and 19.