CVE-2013-1888
Published Aug 16, 2013
·Updated
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
Affected Software
5 affected componentsFixes available
pip/pip<1.3
1.3
pypa pip<1.3
Fedoraproject Fedora=17
Fedoraproject Fedora=18
Fedoraproject Fedora=19
Remediation
Patch Available
Patch Available
Event History
Aug 16, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
May 13, 2022
Advisory Published
via GitHub·01:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2013-1888?
CVE-2013-1888 is considered a moderate severity vulnerability due to its potential for local users to gain unauthorized access to files.
2
How do I fix CVE-2013-1888?
To fix CVE-2013-1888, upgrade pip to version 1.3 or higher.
3
Which versions of pip are affected by CVE-2013-1888?
CVE-2013-1888 affects versions of pip before 1.3.
4
Can CVE-2013-1888 be exploited remotely?
CVE-2013-1888 requires local access, so it cannot be exploited remotely.
5
Which Fedora versions are impacted by CVE-2013-1888?
CVE-2013-1888 impacts Fedora versions 17, 18, and 19.