CVE-2014-8991
Published Oct 9, 2013
·Updated
pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.
Affected Software
4 affected componentsFixes available
pip/pip>=1.3<6.0
6.0
debian/python-pip
20.3.4-4+deb11u123.0.1+dfsg-124.2+dfsg-1
pypa pip>=1.3<=1.5.6
Oracle Solaris=11.2
Remediation
Patch Available
Event History
Oct 9, 2013
Data Sourced
via Debian·02:57 AM
SeverityAffected Software
Nov 24, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
May 13, 2022
Advisory Published
via GitHub·01:11 AM
Sep 3, 2025
Data Sourced
via Microsoft·09:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2014-8991?
CVE-2014-8991 has a severity rating of medium due to its potential to cause denial of service.
2
How do I fix CVE-2014-8991?
To fix CVE-2014-8991, upgrade pip to version 6.0 or later.
3
Which versions of pip are affected by CVE-2014-8991?
CVE-2014-8991 affects pip versions from 1.3 through 1.5.6.
4
Can CVE-2014-8991 be exploited remotely?
CVE-2014-8991 cannot be exploited remotely; it requires local user access.
5
What is the impact of CVE-2014-8991 on package installation?
The impact of CVE-2014-8991 is a denial of service which prevents successful package installation.