CVE-2014-8991: Oracle Solaris

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

pip 1.3 through 1.5.6 allows local users to cause a denial of service (prevention of package installation) by creating a /tmp/pip-build-* file for another user.

Affected products

  • Oracle Solaris: version 11.2 only
  • Pypa Pip: from 1.3, up to and including 1.5.6

Published 2014-11-24. Last modified 2026-06-17.