Advisories ยป MGASA-2015-0023

Updated python-pip packages fix CVE-2014-8991

Publication date: 14 Jan 2015
Modification date: 14 Jan 2015
Type: security
Affected Mageia releases : 4
CVE: CVE-2014-8991

Description

Updated python-pip packages fix security vulnerability:

pip 1.3 through 1.5.6 allows local users to cause a denial of service
(prevention of package installation) by creating a /tmp/pip-build-* file for
another user (CVE-2014-8991).
                

References

SRPMS

4/core