CVE-2013-1888 describes a local arbitrary file overwrite vulnerability in pip versions prior to 1.3, affecting products like Fedora and pypa pip. An attacker could exploit this by using a symlink attack within the /tmp/pip-build temporary directory. This vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:N/I:P/A:N), indicating local access and low attack complexity are required, with potential for partial integrity impact. There is no evidence of active exploitation, no known exploit intelligence (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3CPE matchmatch criteria | cpe:2.3:a:pypa:pip:*:*:*:*:*:*:*:* | ||
17CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:17:*:*:*:*:*:*:* | ||
18CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:18:*:*:*:*:*:*:* | ||
19CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:19:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:N/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.