CVE-2013-1888: Fedoraproject Fedora

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

Affected products

  • Fedoraproject Fedora: version 17 only; version 18 only; version 19 only
  • Pypa Pip: before 1.3 (fixed in 1.3)

Published 2013-08-17. Last modified 2026-06-16.