GHSA-4gv5-qhvr-36vv
Dashboard / Vulnerabilities / GHSA-4gv5-qhvr-36vv
GHSA-4gv5-qhvr-36vv
Summary: Improper Link Resolution Before File Access in pip
Details: pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-1888, https://github.com/pypa/pip/issues/725, https://github.com/pypa/pip/pull/734/files, https://github.com/pypa/pip/pull/780/files, https://github.com/advisories/GHSA-4gv5-qhvr-36vv, https://github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2013-9.yaml, https://github.com/pypa/pip, http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105952.html, http://lists.fedoraproject.org/pipermail/package-announce/2013-May/105989.html, http://lists.fedoraproject.org/pipermail/package-announce/2013-May/106311.html, http://www.openwall.com/lists/oss-security/2013/03/22/10
Affected packages
Package
Name: pip
Purl: pkg:pypi/pip
Affected ranges
Type: ECOSYSTEM
Events:
