CVE-2013-1888

low
Published 2022-05-13 · Modified 2023-11-08
CVSS v3
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2
2.1
VIR risk
2.1

Description

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-1888

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/pypa/pip/pull/780/files

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/pypa/pip/pull/734/files

OS impact

OSVersionStatusFixed in
fedora fedora17affected
fedora fedora18affected
fedora fedora19affected
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
python PyPIpip<1.31.3

Application impact

VendorProductVersionsFixed
pypapip{"endExcluding":"1.3"}1.3

References

CWEs

CWE-59

Verify integrity in audit chain (admin only). AS-IS.