Moderate severityNVD Advisory· Published Aug 17, 2013· Updated Jun 16, 2026
CVE-2013-1888
CVE-2013-1888
Description
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pipPyPI | < 1.3 | 1.3 |
Affected products
5cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- github.com/pypa/pip/pull/734/filesnvdPatchThird Party AdvisoryWEB
- github.com/pypa/pip/pull/780/filesnvdPatchThird Party AdvisoryWEB
- lists.fedoraproject.org/pipermail/package-announce/2013-May/105952.htmlnvdThird Party AdvisoryWEB
- lists.fedoraproject.org/pipermail/package-announce/2013-May/105989.htmlnvdThird Party AdvisoryWEB
- lists.fedoraproject.org/pipermail/package-announce/2013-May/106311.htmlnvdThird Party AdvisoryWEB
- www.openwall.com/lists/oss-security/2013/03/22/10nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-4gv5-qhvr-36vvghsaADVISORY
- github.com/pypa/pip/issues/725nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2013-1888ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/pip/PYSEC-2013-9.yamlghsaWEB
News mentions
0No linked articles in our index yet.